gotland.se
HTML metadata
Technology
- Server
- baffin-bay-inlet
- Stack
- Java
Third-party hosts loaded (2)
- static.rekai.se×2
- f1-eu.readspeaker.com×1
Social
Contact
- Phone
DNS records live
- NS
-
- dns6.telia.com
- ns.gotland.se
- ns2.gotland.se
- MX
-
- 10 mail.gotland.se
- 20 mail2.gotland.se
- TXT
-
Show 4 TXT records
q8PXzLlg+WEOikd5pZznA9+GFFO9CTEPuXbYrLjnekQtEaVPO86o0Gf5G4XiFs61QyIihCeVnZFa8AruARqZJA==DirectFedAuthUrl=https://idp2.gotland.se/wa/auth/saml/MS=47B6E49F6F02EB86ABB56CC1D1B3F699AC25516ESLCm/S4LDpXfhWq2GKrpmYSSwWUujMSIxBV1NuLVfLCvleDgMfdJfI2SZNGh6K2RQXkGWMZOhP5Zmeh+os89Hg==
- Verified for
-
- Apple
- GlobalSign
- Microsoft 365
Email authentication partial
- SPF
-
v=spf1 mx a ip4:212.247.85.136 ip4:193.11.12.148 ip4:46.59.104.5 ip4:91.123.56.128 ip4:185.84.1.202 ip4:212.85.68.72 include:spf.protection.outlook.com include:mg-lcsse.tietoevry.com include:_spf.ungapped.io -allstrict (-all) - DMARC
-
v=DMARC1; p=none; rua=mailto:spam@gotland.se;policy: none (monitoring only) - DKIM
- no key found at common selectors
Certificate (current)
E8
Expires in 31 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Permissions Policy
Header values
- referrer-policy
no-referrer- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://svanalytics.containers.piwik.pro/2479d5f4-1a62-42bf-91c4-e6075dc3f52b.js https://svanalytics.containers.piwik.pro/ppms.js https://*.rekai.se https://*.readspeaker.com https://maps.googleapis.com https://micc.gotland.se https://map-embed.naturkartan.se https://player.vimeo.com https://mfstatic.com https://www.youtube.com https://s.ytimg.com https://static.ws.apsis.one https://code.highcharts.com/highcharts.js https://reseplanerare.resrobot.se https://public.flourish.studio/resources/; frame-src 'self' https://*.vimeo.com https://*.youtube.com https://youtube.com https://*.spotify.com https://*.podbean.com https://*.screen9.com https://*.gotland.se https://*.inviewer.se https://*.svt.se https://*.naturkartan.se https://play.google.com https://datawrapper.dwcdn.net https://svanalytics.piwik.pro https://app-eu.readspeaker.com https://menu.matildaplatform.c- strict-transport-security
max-age=31536000; includeSubDomains; preload