globalcompact.se
HTML metadata
Technology
- Server
- nginx
- CMS
- WordPress 6.5.5
- PHP
- 8.2.30 security-only
Third-party hosts loaded (1)
- www.google.com×1
Social
DNS records live
- NS
-
- ns1.loopia.se
- ns2.loopia.se
- MX
-
- 10 globalcompact-se.mail.protection.outlook.com
- TXT
-
pardot1054433=0a4608cd4cdd169630ddcff2e026c3c8ef2761349d46e856a88a005cdeeb71b8linkedin-site-verification=ec5a6eb5-7105-4ef2-b83d-c0db49b6fbf4sending_domain1054433=215b81bfee4e37d93cb8850706d2654cf7a7acacdcaee634bd75ea0b0516f9f4
- Verified for
-
- Microsoft 365
Email authentication partial
- SPF
-
v=spf1 include:spf.protection.outlook.com include:aspmx.pardot.com include:_spf.salesforce.com ip4:128.245.247.12 -allstrict (-all) - DMARC
-
v=DMARC1; p=none; pct=100; rua=mailto:re+welr6epbomc@dmarc.postmarkapp.com; sp=none; aspf=r;policy: none (monitoring only) · sp=none - DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCWnn9jPrxPH8JeIGGakX1hVD6lk0SINoO9agdfxt8ecx3P4W0xGl9zWAoZ0kwqf4H46xa3SxtXCaDnPyaMDy… - k2:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAv2aC2KjGKLOwTweBY5A9RpjsxaBXR9r7OAU6U8/zn92ivImI75naUujWbItRI/QmL1jy5PWGqLwoUA…
selectors probed - selector1:
Certificate (current)
R12
Expires in 61 days
HTTP security headers
- present
-
- content-security-policy
- x-frame-options
- x-content-type-options
- findings
-
- missing HSTS
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src 'self'; img-src https: data:; frame-src 'self' https://bid.g.doubleclick.net https://youtube.com https://www.youtube.com http://*.invajo.com https://*.invajo.com https://consentcdn.cookiebot.com https://www.google.com https://*.globalcompact.se https://*.zoom.us; media-src https: data:; script-src 'self' 'unsafe-eval' 'unsafe-inline' https://tagmanager.google.com https://*.googletagmanager.com https://www.google-analytics.com https://ssl.google-analytics.com https://www.googleadservices.com https://www.google.com https://googleads.g.doubleclick.net https://consent.cookiebot.com https://consentcdn.cookiebot.com https://snap.licdn.com https://*.globalcompact.se https://px.ads.linkedin.com https://www.gstatic.com https://cdn.usefathom.com https://pi.pardot.com; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com https://*.g.doubleclick.net https://*.google.com ht