herrforsnat.fi
HTML metadata
Technology
- CMS
- WordPress
- jQuery
- 3.7.1
- Analytics
-
- Google Tag Manager
Third-party hosts loaded (3)
- www.herrfors.fi×4
- herrfors-48hd.aiagent.fi×2
- www.googletagmanager.com×1
Social
Contact
- Phone
DNS records live
- NS
-
- ns1.multi.fi
- ns1.z.fi
- ns2.multi.fi
- ns2.z.fi
- ns3.multi.fi
- ns4.multi.fi
- MX
-
- 5 mx1.hc1313-29.c3s2.iphmx.com
- 5 mx2.hc1313-29.c3s2.iphmx.com
- Verified for
-
- GlobalSign
- Meta
Email authentication strong
- SPF
-
v=spf1 exists:%{i}.spf.hc1313-29.c3s2.iphmx.com -allstrict (-all) - DMARC
-
v=DMARC1; p=reject; pct=100; fo=1; ri=3600; rua=mailto:6252c846@inbox.ondmarc.com,mailto:oy-herrfors-ab@rua.dmp.cisco.com; ruf=mailto:6252c846@inbox.ondmarc.com,mailto:oy-herrfors-ab@ruf.dmp.cisco.com;policy: reject (enforced) - DKIM
- no key found at common selectors
Certificate (current)
E7
Expires in 74 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- short HSTS max-age
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN- permissions-policy
accelerometer=(),autoplay=(self),camera=(),display-capture=(),encrypted-media=(),fullscreen=(*),geolocation=(),gyroscope=(),magnetometer=(),microphone=(),midi=(),payment=(),picture-in-picture=(),publickey-credentials-get=(),screen-wake-lock=(),sync-xhr=(self),usb=(),xr-spatial-tracking=()- x-content-type-options
nosniff- content-security-policy
style-src fonts.googleapis.com *.hotjar.com 'self' p.typekit.net use.typekit.net googletagmanager.com www.googletagmanager.com tagmanager.google.com 'unsafe-inline';font-src fonts.gstatic.com *.hotjar.com 'self' use.typekit.net data:;script-src connect.facebook.net *.hotjar.com https://*.clarity.ms https://c.bing.com 'self' *.googletagmanager.com *.googleadservices.com *.google-analytics.com *.analytics.google.com *.g.doubleclick.net *.google.com pagead2.googlesyndication.com www.googleadservices.com www.google.com www.googletagmanager.com googleads.g.doubleclick.net 'nonce-QrerU3IuI1L5i6RS0Q0dUdCxEMAk1D5x' 'strict-dynamic';frame-src www.facebook.com *.hotjar.com 'self' *.googletagmanager.com *.googleadservices.com td.doubleclick.net www.youtube.com www.googletagmanager.com kiinnitys.herrfors.fi herrfors.teamtailor.com careers.herrfors.fi;form-action www.facebook.com 'self' tunnistus.telia.fi;img-src www.facebook.com *.hotjar.com https://*.clarity.ms https://c.bing.com 'self' *.googlet- strict-transport-security
max-age=300; includeSubDomains; preload