fanger.no
HTML metadata
Technology
- CMS
- Next.js
- JS framework
- Next.js, React
- Analytics
-
- Google Tag Manager
- Fonts
-
- Google Fonts
Third-party hosts loaded (3)
- fonts.gstatic.com×1
- www.freeprivacypolicy.com×1
- www.googletagmanager.com×1
Social
Registration
- Registrar
- Domeneshop AS
- Created
- 2019-11-13
- Updated
- 2026-03-20
- Name servers
-
- ns1.hyp.net
- ns3.hyp.net
- ns2.hyp.net
DNS records live
- NS
-
- ns1.hyp.net
- ns2.hyp.net
- ns3.hyp.net
- MX
-
- 10 mx.domeneshop.no
Email authentication weak
- SPF
- not published
- DMARC
- not published
- DKIM
-
- s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAn6g8+v/YVdQmC0F88LMqclmfySMgdUGyUQIKrpMRzlhPUFw0wZvtUDjjYuTma0SnwFYQlpfY1EVJOFt6LT… - s2:
k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDNVbzaWajKBgwrxKHFlj1isY/kv40u4Y6qJOKaaVxWQoPN0p3SD85Ojf2sr/vnlhRLLS7ytNlIzgS5uWjyfuUYhy…
selectors probed - s1:
Certificate (current)
R12
Expires in 53 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Permissions Policy
Header values
- referrer-policy
no-referrer-when-downgrade- x-frame-options
deny- x-content-type-options
nosniff- content-security-policy
default-src 'self'; frame-src https://youtu.be https://www.youtube.com https://player.vimeo.com https://vimeo.com https://media.digitalarkivet.no https://digitalarkivet.no https://www.freeprivacypolicy.com https://region1.google-analytics.com https://www.google-analytics.com; media-src https://media.digitalarkivet.no https://digitalarkivet.no; connect-src 'self' https://api.fanger.no/api https://testapi.fanger.no https://api.fanger.no https://www.google-analytics.com https://www.googletagmanager.com https://region1.google-analytics.com https://*.google-analytics.com https://maps.googleapis.com https://maps.gstatic.com https://fonts.googleapis.com https://fonts.gstatic.com https://*.algolia.net https://*.algolianet.com https://youtu.be https://www.youtube.com https://player.vimeo.com https://vimeo.com https://media.digitalarkivet.no https://digitalarkivet.no https://www.freeprivacypolicy.com; script-src 'self' 'unsafe-eval' 'unsafe-inline' https://www.google-analytics.com https://www.go- strict-transport-security
max-age=15724800; includeSubDomains