helfo.no

.no crawl

First seen 2026-06-03 · Last seen 2026-06-03 · ok HTTP/1.1 200 893 ms crawled 2026-06-03

US · 151.101.131.52 · AS54113 Fastly, Inc.

Reputation 100/100

Classifying

HTML metadata

Title
Helfo
Description
Her finner lege, fysioterapeut, tannlege, psykolog og andre helseaktører informasjon om Helfos tjenester, som refusjon av utgifter for pasientbehandling, regelverk, takstbruk og andre forhold.
Language
no

Open Graph

url
https://www.helfo.no/
title
Helfo
locale
no
site name
Helfo
description
Her finner lege, fysioterapeut, tannlege, psykolog og andre helseaktører informasjon om Helfos tjenester, som refusjon av utgifter for pasientbehandling, regelverk, takstbruk og andre forhold.

Technology

Server
Apache
CMS
Gatsby
Analytics
  • Google Analytics
  • Google Tag Manager

Third-party hosts loaded (3)

  • unpkg.com×2
  • www.google-analytics.com×1
  • www.googletagmanager.com×1

Social

Registration

Registrar
Norsk Helsenett SF
Created
2020-10-29
Updated
2025-10-29
Name servers
  • nsx1.nhn.no
  • nsx2.nhn.no

DNS records live

NS
  • nsx1.nhn.no
  • nsx2.nhn.no
MX
  • 0 helfo-no.mail.protection.outlook.com
TXT
Show 5 TXT records
  • 97d397e94fca4b6bbbc5650dc1b00443765aa94ed4b1b87c8f384277acdccbc6
  • 9f53d2cc31f73b50e8141800c36e6361488b6411fe5216b2cee5c78264bb648f
  • Foxit-domain-verification=923c03c7fd0a2f14041f5cd5b04f7ba0
  • 39a4e37e1c7fa51f4fba01d2f09e81904e368d0f4f7063aa1b6370d5abfe33e1
  • 03a5ea20926530d5602a68c3039c4575e937e712c2a1d0c835ecc27ea47f92b8
Verified for
  • Atlassian
  • Google

Email authentication strong

SPF
v=spf1 ip4:185.38.121.20/30 ip6:2a04:6fb0:121::21/126 ip4:62.92.2.88 ip4:91.186.79.137 a:outmail.easycruit.com include:_spf.easycruit.com include:spf.protection.outlook.com include:_spf.nhn.no include:_spf.sndr.no include:spf.logicalware.com ~all
softfail (~all)
DMARC
v=DMARC1; p=reject; sp=reject; rua=mailto:dsm1h58m@ag.dmarcian.com; ruf=mailto:dmarcian@helsedir.no;
policy: reject (enforced) · sp=reject
DKIM
  • selector1: v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQC9m2Xj6iB5uOYGw5cPg3506qOTwdmOcZtroVueT8pTn0zrnEvMxemCj6B5VD6yyCj6la97P8CdmAqMr7jwJy…
  • s1: k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEArD4rN2kHjDfxLrIM6IlrBrzRTYjHwCoyqaz8zNirNqSwZg0kgJb60GQ9GU63umkP0xw6hdcLwBWzXs3U8W…
  • s2: k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAxR4UM80u1I2R0F97HKLQozzyqJHHYTaUhxw6UvIdgfzMtYKYLT6Bvbj0Ij/zLh0MG5KI8LtJc2nAKFyl8+…
selectors probed

Certificate (current)

R12
from 2026-04-19 to 2026-07-18
Expires in 43 days

HTTP security headers

Header hygiene 80/100 Checked live page: https://www.helfo.no/

present
  • strict-transport-security
  • content-security-policy
  • x-frame-options
  • x-content-type-options
findings
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
  • missing Referrer Policy
  • missing Permissions Policy
Header values
x-frame-options
DENY
x-content-type-options
nosniff
content-security-policy
base-uri 'self' *.uxtweak.com;default-src 'self' *.tagmanager.google.com *.googletagmanager.com;font-src 'self' fonts.gstatic.com data:;form-action 'self' 'unsafe-inline' export.highcharts.com/ data:;frame-src 'self' *.brightcove.net bcove.video *.youtube.com *.vimeo.com *.powerbi.com *.google.com statistikk.helsedirektoratet.no data: blob:;img-src 'self' *.siteimproveanalytics.io *.google-analytics.com *.tagmanager.google.com *.googletagmanager.com *.vimeocdn.com *.uxtweak.com data:;object-src 'none';script-src 'self' 'unsafe-inline';style-src 'self' 'unsafe-inline' *.tagmanager.google.com https://parsleyjs.org/src/parsley.css https://fonts.googleapis.com;script-src-elem 'self' 'unsafe-inline' https://www.google-analytics.com https://www.googletagmanager.com https://siteimproveanalytics.com *.uxtweak.com code.highcharts.com/ https://www.google.com/recaptcha/api.js https://www.gstatic.com/recaptcha/ https://cdn.jsdelivr.net/npm/bootstrap@3.4.1/dist/js/bootstrap.min.js *.skyra.no https:
strict-transport-security
max-age=31557600

Links to (2)

Linked from (1)