fjallexpressen.se
HTML metadata
Technology
- Server
- nginx
- Analytics
-
- Google Tag Manager
- Fonts
-
- Google Fonts
Third-party hosts loaded (7)
- static.saveacdn.se×11
- public.saveacdn.se×3
- fonts.googleapis.com×2
- savea.objects.dc-fbg1.glesys.net×2
- fonts.gstatic.com×1
- js-de.sentry-cdn.com×1
- www.googletagmanager.com×1
Contact
- Phone
DNS records live
- NS
-
- dns01.dipcon.com
- dns02.ports.se
- dns03.ports.se
- dns04.ports.net
- MX
-
- 10 fjallexpressen-se.mail.protection.outlook.com
- TXT
-
Show 4 TXT records
CMPrGR7OsxCGpER2Hn5ZQ6TEcvHlHBp7TCoBWBFvOx3hNP9K7WVfW3jjQNlTIMs35JZYNfCRgP9rwttE0dtLbA==WZa6WbGP5PsyJuQ4oeoV4nwBG48JsI3kpP4o6YEH6SJuXKHsDYxfWU0wwRxfp+spyr1NAMd0OGe/Ftg96tfeFg==hZpvSHPC9Plcan//iG4n8jRQIzr+7mCHr+4VZJYxfGBp3zdhatGmnSqMeKbNKhioDoz0SlBgQSmWNHTDkWlJSg==include:spf-eu.emailsignatures365.com
Email authentication partial
- SPF
-
v=spf1 ip4:194.237.103.120/32 ip4:194.237.103.126/32 include:spf.protection.outlook.com include:spf.savea.se a:webmail.bergkvarabuss.se a:m1.bergkvarabuss.se include:all._spf.plma.se include:spf-eu.emailsignatures365.com ~allsoftfail (~all) - DMARC
-
v=DMARC1;p=none;sp=none;adkim=r;aspf=r;pct=100;fo=1;rf=afrf;ri=86400;rua=mailto:dmarc_agg@vali.email;ruf=mailto:dmarc@bergkvarabuss.sepolicy: none (monitoring only) · sp=none - DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQC7HuBdu3Iex+MdPVeNmiIDMKC3BFAcG/hoUAqO+oFTF/C89nmH5QwJMvSF4xME8U/Qj++cyP0w8AhvYchnXS… - selector2:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDGdUVjx+1LxPsv0efIfLYb3Fl6KpIbL2qZme6xKT1yFkWENnHT3AYrzh3a2sqgXCVBZI4JackcSsMfp1cj+9…
selectors probed - selector1:
Certificate (current)
R13
Expires in 68 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Permissions Policy
Header values
- referrer-policy
strict-origin- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src 'self'; img-src * data: https://*.google-analytics.com/ https://*.googletagmanager.com https://googleads.g.doubleclick.net/ https://www.google.com https://google.com; media-src *; frame-src *; style-src * 'unsafe-inline'; font-src *; script-src https://static.saveacdn.se/ https://savea.objects.dc-fbg1.glesys.net/ 'unsafe-inline' https://browser.sentry-cdn.com https://js-de.sentry-cdn.com https://*.googletagmanager.com/ https://www.googleadservices.com/ https://www.google.com/ https://maps.googleapis.com/ https://*.facebook.net/ https://facebook.net/ https://*.facebook.com/ https://facebook.com/; connect-src 'self' *.sentry.io https://*.google-analytics.com/ https://*.analytics.google.com/ https://*.googletagmanager.com/ https://maps.googleapis.com/- strict-transport-security
max-age=31536000
Links to (1)
Linked from (1)
- savea.se×1