helfo.no
HTML metadata
Technology
- Server
- Apache
- CMS
- Gatsby
- Analytics
-
- Google Analytics
- Google Tag Manager
Third-party hosts loaded (3)
- unpkg.com×2
- www.google-analytics.com×1
- www.googletagmanager.com×1
Social
Registration
- Registrar
- Norsk Helsenett SF
- Created
- 2020-10-29
- Updated
- 2025-10-29
- Name servers
-
- nsx1.nhn.no
- nsx2.nhn.no
DNS records live
- NS
-
- nsx1.nhn.no
- nsx2.nhn.no
- MX
-
- 0 helfo-no.mail.protection.outlook.com
- TXT
-
Show 5 TXT records
97d397e94fca4b6bbbc5650dc1b00443765aa94ed4b1b87c8f384277acdccbc69f53d2cc31f73b50e8141800c36e6361488b6411fe5216b2cee5c78264bb648fFoxit-domain-verification=923c03c7fd0a2f14041f5cd5b04f7ba039a4e37e1c7fa51f4fba01d2f09e81904e368d0f4f7063aa1b6370d5abfe33e103a5ea20926530d5602a68c3039c4575e937e712c2a1d0c835ecc27ea47f92b8
- Verified for
-
- Atlassian
Email authentication strong
- SPF
-
v=spf1 ip4:185.38.121.20/30 ip6:2a04:6fb0:121::21/126 ip4:62.92.2.88 ip4:91.186.79.137 a:outmail.easycruit.com include:_spf.easycruit.com include:spf.protection.outlook.com include:_spf.nhn.no include:_spf.sndr.no include:spf.logicalware.com ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=reject; sp=reject; rua=mailto:dsm1h58m@ag.dmarcian.com; ruf=mailto:dmarcian@helsedir.no;policy: reject (enforced) · sp=reject - DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQC9m2Xj6iB5uOYGw5cPg3506qOTwdmOcZtroVueT8pTn0zrnEvMxemCj6B5VD6yyCj6la97P8CdmAqMr7jwJy… - s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEArD4rN2kHjDfxLrIM6IlrBrzRTYjHwCoyqaz8zNirNqSwZg0kgJb60GQ9GU63umkP0xw6hdcLwBWzXs3U8W… - s2:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAxR4UM80u1I2R0F97HKLQozzyqJHHYTaUhxw6UvIdgfzMtYKYLT6Bvbj0Ij/zLh0MG5KI8LtJc2nAKFyl8+…
selectors probed - selector1:
Certificate (current)
R12
Expires in 43 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
DENY- x-content-type-options
nosniff- content-security-policy
base-uri 'self' *.uxtweak.com;default-src 'self' *.tagmanager.google.com *.googletagmanager.com;font-src 'self' fonts.gstatic.com data:;form-action 'self' 'unsafe-inline' export.highcharts.com/ data:;frame-src 'self' *.brightcove.net bcove.video *.youtube.com *.vimeo.com *.powerbi.com *.google.com statistikk.helsedirektoratet.no data: blob:;img-src 'self' *.siteimproveanalytics.io *.google-analytics.com *.tagmanager.google.com *.googletagmanager.com *.vimeocdn.com *.uxtweak.com data:;object-src 'none';script-src 'self' 'unsafe-inline';style-src 'self' 'unsafe-inline' *.tagmanager.google.com https://parsleyjs.org/src/parsley.css https://fonts.googleapis.com;script-src-elem 'self' 'unsafe-inline' https://www.google-analytics.com https://www.googletagmanager.com https://siteimproveanalytics.com *.uxtweak.com code.highcharts.com/ https://www.google.com/recaptcha/api.js https://www.gstatic.com/recaptcha/ https://cdn.jsdelivr.net/npm/bootstrap@3.4.1/dist/js/bootstrap.min.js *.skyra.no https:- strict-transport-security
max-age=31557600