gsv.dk
HTML metadata
Technology
- CMS
- WordPress
Third-party hosts loaded (3)
- gsv-imgix.imgix.net×8
- dreambroker.com×2
- gmpg.org×1
DNS records live
- NS
-
- ns01.one.com
- ns02.one.com
- MX
-
- 10 dk.mx1.mailanyone.net
- 20 dk.mx2.mx25.net
- 30 dk.mx3.mailanyone.net
- 40 dk.mx4.mx25.net
- TXT
-
Show 5 TXT records
google-site-verification=-DStdmF-_Dtd3lQ87gO_lH3XrXb0MN5gTcP2baMGgSYapple-domain-verification=Yq6B0qQ0XRQBzpKLms-domain-verification=974df531-2de6-4e2c-b5c8-bbda8d079bcf_globalsign-domain-verification=nZwVi8ea6rTxg3N4ztoFwQptjQ4py57_qKCoYANywLgoogle-site-verification=sXgRD7dO4eFCXLEFvaOwa8_-x-lI18lxS5XeyFb-b34
Email authentication strong
- SPF
-
v=spf1 ip4:62.243.129.131 ip4:3.67.54.56 ip4:3.65.81.9 include:spf.sosafe.de include:spf.mailanyone.net include:mailmailmail.net include:_spf.online.superoffice.com include:spf.protection.outlook.com -allstrict (-all) - DMARC
-
v=DMARC1; p=reject; rua=mailto:411e93a49363311@rep.dmarcanalyzer.com,mailto:dmarc_agg@vali.email; ruf=mailto:411e93a49363311@for.dmarcanalyzer.com;policy: reject (enforced) - DKIM
-
Show 4 DKIM selectors
- selector1:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCKfZRT9sfbA4N2ySGQ+P8Bi4wksor+tMUvY4w+0owc2MrGeHRhL7a7pY5a4D4rKaUOja6CnUzCPrK+SnYc+8… - selector2:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCtyH5tuLF05BnhWACDAqSQ6fuf/dG2ufvESIbuItRt0UKGnFK64Va2SSTsAyMyOjbVlnXlIChc+9gB6HUUS1… - s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA1pucBOqgHHnQKNjHr33w0AFCWQBfhAx3Ic5QYFEywZJAW3Yo1Hga8HgeoXBut/yvWG9Wi5mWx0wRbpcuLW… - s2:
k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDDSZAfjkVw8c6TKgqgi1ExXOIfV7YnKqX3L+huOWLPPk+yKZX3fFN6RXBmCW/ggKC7W/3Wb9MtcjnMNu/4+l9AgC…
selectors probed - selector1:
Certificate (current)
E8
Expires in 67 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
DENY- x-content-type-options
nosniff- content-security-policy
script-src 'self' 'unsafe-inline' 'unsafe-eval' www.google-analytics.com ajax.googleapis.com maps.googleapis.com js-agent.newrelic.com flow.gsv.dk sdk.privacy-center.org www.googletagmanager.com *.adform.net api.ipify.org *.doubleclick.net *.google.com *.googleadservices.com *.google-analytics.com *.g.doubleclick.net www.clarity.ms; frame-src 'self' dreambroker.com *.doubleclick.net *.googletagmanager.com gsv.eu.auth0.com auth.gsv.dk; frame-ancestors 'self'; worker-src 'self' blob:- strict-transport-security
max-age=31536000; includeSubDomains; preload