fhs.se
HTML metadata
Technology
- Stack
- Java
- Analytics
-
- Google Tag Manager
Third-party hosts loaded (3)
- www.gstatic.com×2
- static.rekai.se×1
- www.googletagmanager.com×1
Contact
- Phone
DNS records live
- NS
-
- ns1.fhs.se
- ns2.fhs.se
- sunic.sunet.se
- MX
-
- 10 fhs-se.mail.protection.outlook.com
- TXT
-
Show 6 TXT records
VZfVZz6ovi8MxQX/ST91ouCXXgT+BGqoIkGYDI4WOcbOWMIXnao+9KwXTV6itHvDMD1ll3GHw+QX/I6hjaiuJQ==mentimeter-2cc9001b-7981-4681-bb01-82b1b9c41e65lime-domain-verification=43E54808FAADB93240482f1-b8d8-4075-9f23-eebdf09d98faDomainVerification=2Q7GHQW17L5MG65Z6POYJINFZCI78BJINFZ94K5R3VVHGJ2I090ZN1YFX5MEUQVVz5dyz7hq9sa5yjyxjwnggr59py6u3
- Verified for
-
- Adobe
- Anthropic
- Apple
- Meta
- OpenAI
- Zoom
Email authentication strong
- SPF
-
v=spf1 ip4:130.242.58.0/24 ip6:2001:06b0:0009:3610::/64 include:spf.bedrock.lime-technologies.com include:servers.mcsv.net include:spf.multinet.com include:spf.protection.outlook.com ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=reject; pct=100; rua=mailto:dmarc_agg@vali.email,mailto:dmarc@fhs.se; sp=quarantine; aspf=r;policy: reject (enforced) · sp=quarantine - DKIM
-
- default:
v=DKIM1; k=rsa;p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDkG5dm64J80Ht+8mUQZe/MkSj3z68Td4X7yhbnZlwbwaSr0xj4e6cTMot7Zikc3RNgv6nLQ4O6hVLnk5pXyIu… - selector1:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDn0wSjs0r28XFuAKt6oSZ6IER8nnOzpiAsKGwa5LxeDWD2JDmQc7tH53E+Ulxh5ec8ye/mYrgeY689U9SCUu… - k2:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAv2aC2KjGKLOwTweBY5A9RpjsxaBXR9r7OAU6U8/zn92ivImI75naUujWbItRI/QmL1jy5PWGqLwoUA…
selectors probed - default:
Certificate (current)
GEANT TLS RSA 1
Expires in 192 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
same-origin- x-frame-options
SAMEORIGIN- permissions-policy
geolocation=(), microphone=(self *.imbox.io), camera=(self *.imbox.io), payment=(), usb=()- x-content-type-options
nosniff- content-security-policy
default-src 'none'; base-uri 'self'; upgrade-insecure-requests; script-src 'self' 'unsafe-inline' 'unsafe-eval' cookiehub.net cdn.cookiehub.eu; script-src-elem 'self' 'unsafe-inline' 'unsafe-eval' cookiehub.net cdn.cookiehub.eu *.googletagmanager.com *.gstatic.com *.readspeaker.com *.imbox.io connect.facebook.net *.hotjar.com mfstatic.com *.rekai.se *.google.com formconnector.com web103.reachmee.com; worker-src 'self' blob:; connect-src 'self' *.google-analytics.com *.gstatic.com *.mediaflow.com *.mediaflowpro.com mfstatic.com *.readspeaker.com *.rekai.se ds.cookiehub.net consent.cookiehub.net region-eu.cookiehub.net consent-eu.cookiehub.net cookiehub.net cdn.cookiehub.eu *.formconnector.com *.hotjar.com *.hotjar.io wss://*.hotjar.com files.imbox.io; style-src 'self' 'unsafe-inline' fonts.googleapis.com *.readspeaker.com cookiehub.net cdn.cookiehub.eu mfstatic.com *.mediaflow.com *.mediaflowpro.com *.hotjar.com; font-src 'self' data: fonts.gstatic.- strict-transport-security
max-age=31536000
Linked from (1)
- kks.se×1