fynbus.dk
HTML metadata
Technology
Third-party hosts loaded (5)
- static.moliri.dk×15
- cdn.moliri.dk×4
- cdnjs.cloudflare.com×2
- cookiecontrol.bleau.dk×2
- cdn.jsdelivr.net×1
Social
DNS records live
- NS
-
- ns1.netsite.dk
- ns2.netsite.eu
- ns3.netsite.se
- MX
-
- 10 mx1-dk.centerasecurity.dk
- 10 mx2-dk.centerasecurity.dk
- 20 mx3-dk.centerasecurity.dk
- TXT
-
bw=5nUbkMDeVSxM7foolB0wUnyKnnuRkq9EoAqcgBw1iBVrywA0c2PGr7rORRDK8qAS16IB410UEC8P/j7vZs9EZjnICjx8+V/oX6vT7luLHFiduQ+9mew+vapiB4R6QXl0Ng==
- Verified for
-
- Microsoft 365
Email authentication strong
- SPF
-
v=spf1 include:_spf26690.spfprotect.com -allstrict (-all) - DMARC
-
v=DMARC1; p=reject; rua=mailto:65b906ec4feb7@dmarc-dk.centerasecurity.com;policy: reject (enforced) - DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCf802WG6SVvfKoTlm8O/oaCUQl6IBMluI/Lh+9EL83xkc5MiSEJf35Df2oDFTgCtXxCu+nYW4BZphLEU4UOv… - k2:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAv2aC2KjGKLOwTweBY5A9RpjsxaBXR9r7OAU6U8/zn92ivImI75naUujWbItRI/QmL1jy5PWGqLwoUA…
selectors probed - selector1:
Certificate (current)
GeoTrust TLS RSA CA G1
Expires in 75 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing frame protection
Header values
- referrer-policy
strict-origin-when-cross-origin- permissions-policy
accelerometer=(self), camera=(self), geolocation=(self), gyroscope=(self), magnetometer=(self), microphone=(self), payment=(self), usb=(self)- x-content-type-options
nosniff- content-security-policy
default-src 'self' fonts.gstatic.com fonts.googleapis.com static.moliri.dk *.azure.com *.google-analytics.com *.doubleclick.net data: www.gstatic.com statservicefunctions.azurewebsites.net hearingportalfilestorage.blob.core.windows.net cookiecontrol.bleau.dk *.devtunnels.ms api-eu1.cludo.com *.moliri.dk dawa.aws.dk cdn.jsdelivr.net cdnjs.cloudflare.com moliricdn.azurewebsites.net *.plumsail.com public-transportapi-dev.azurewebsites.net forms.plumsail.com static2.sharepointonline.com public-transportapi-dev-test.azurewebsites.net publictransportapi-prod.azurewebsites.net publictransportapi-prod-pipeline-staging.azurewebsites.net localhost:7277;style-src 'self' 'unsafe-inline' fonts.googleapis.com cdhsign.dk cdnjs.cloudflare.com unpkg.com static.moliri.dk customer.cludo.com *.gstatic.com npmcdn.com moliricdn.azurewebsites.net *.plumsail.com plumsailforms.blob.core.windows.net *.youtube.com *.vimeo.com *.google.com forms.plumsail.com;script-src 'self' 'unsafe-inline' *.moliri.dk *.bleau.d- strict-transport-security
max-age=31536000; includeSubDomains; preload