granoshop.fi
HTML metadata
Technology
- CDN
- Amazon CloudFront
- Server
- CloudFront
- Analytics
-
- Google Tag Manager
Third-party hosts loaded (4)
- app.mygrano.fi×4
- thumb.mygrano.fi×2
- status.mygrano.fi×1
- www.googletagmanager.com×1
DNS records live
- NS
-
- ns-1161.awsdns-17.org
- ns-1879.awsdns-42.co.uk
- ns-38.awsdns-04.com
- ns-725.awsdns-26.net
- MX
-
- 10 inbound-smtp.eu-west-1.amazonaws.com
- Verified for
-
- Meta
Email authentication weak
- SPF
- not published
- DMARC
- not published
- DKIM
- no key found at common selectors
Certificate (current)
Amazon RSA 2048 M01
Expires in 166 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- content-security-policy-report-only
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- CSP uses wildcard sources
- missing Permissions Policy
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
DENY- x-content-type-options
nosniff- content-security-policy
default-src 'self'; base-uri 'self' https://524565.hs-sites-eu1.com; font-src 'self' https://app.mygrano.fi https://*.hotjar.com https://fonts.gstatic.com data: https://*.hs-sites-eu1.com https://use.typekit.net; script-src https://app.mygrano.fi 'nonce-2c1046f9-457d-4937-b480-3fa1ea14ed06' 'strict-dynamic' 'report-sample' 'unsafe-eval' https://googletagmanager.com https://tagmanager.google.com https://*.googletagmanager.com https://www.google-analytics.com https://ssl.google-analytics.com https://www.googleadservices.com https://www.google.com https://googleads.g.doubleclick.net https://pagead2.googlesyndication.com https://partner.googleadservices.com https://tpc.googlesyndication.com https://www.googletagservices.com https://adservice.google.com https://adservice.google.fi; connect-src https://app.mygrano.fi 'self' data: blob: https://thumb.mygrano.fi https://ecommerce.emmi.fi https://static.paytrail.com https://resources.paytrail.com https://editor.mygrano.fi https://granoshop.fi/d- strict-transport-security
max-age=63072000; includeSubDomains; preload- content-security-policy-report-only
default-src 'self'; base-uri 'self' https://524565.hs-sites-eu1.com; font-src 'self' https://app.mygrano.fi https://*.hotjar.com https://fonts.gstatic.com data: https://*.hs-sites-eu1.com https://use.typekit.net; script-src https://app.mygrano.fi 'nonce-2c1046f9-457d-4937-b480-3fa1ea14ed06' 'strict-dynamic' 'report-sample' 'unsafe-eval' https://googletagmanager.com https://tagmanager.google.com https://*.googletagmanager.com https://www.google-analytics.com https://ssl.google-analytics.com https://www.googleadservices.com https://www.google.com https://googleads.g.doubleclick.net https://pagead2.googlesyndication.com https://partner.googleadservices.com https://tpc.googlesyndication.com https://www.googletagservices.com https://adservice.google.com https://adservice.google.fi; connect-src https://app.mygrano.fi 'self' data: blob: https://thumb.mygrano.fi https://ecommerce.emmi.fi https://static.paytrail.com https://resources.paytrail.com https://editor.mygrano.fi https://granoshop.fi/d
Linked from (1)
- grano.fi×1