hugra.no
HTML metadata
Technology
- CMS
- Next.js
DNS records live
- NS
-
- ns1.nordkapp.net
- ns2.nordkapp.net
- MX
-
- 10 mail.protonmail.ch
- 20 mailsec.protonmail.ch
- TXT
-
protonmail-verification=56258af06e9afe788c9fa8d8b8d3f425eab41c38
Email authentication partial
- SPF
-
v=spf1 a mx ip4:185.114.57.56 include:_spf.tem.scaleway.com include:_spf.protonmail.ch include:mailgun.org -allstrict (-all) - DMARC
-
v=DMARC1; p=none;policy: none (monitoring only) - DKIM
-
- s1:
k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAxHwaAv0Tbeev9MaRYxkdg3YtykXAz/OXXGKUCdTWq6xky8CB6sOXvn5iF0gNyUNesIPnSBbvRIIF0D3GsPq0x+v…
selectors probed - s1:
Certificate (current)
R13
Expires in 43 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
no-referrer- x-frame-options
DENY- permissions-policy
geolocation=(), camera=(), microphone=(self), payment=()- x-content-type-options
nosniff- content-security-policy
default-src 'self' blob: data:; script-src 'self' 'nonce-OGU3Y2Q4NWUtMzYwNC00NGIwLTk1MzUtZDE1NGVmMDNmNjk2' 'strict-dynamic' 'wasm-unsafe-eval' blob:; style-src 'self' 'unsafe-inline'; img-src 'self' data: blob: https:; font-src 'self' data:; worker-src 'self' blob:; connect-src 'self' https: data: blob:; frame-ancestors 'none'; base-uri 'self'; form-action 'self' https://www.mollie.com https://*.mollie.com; object-src 'none'- strict-transport-security
max-age=31536000; includeSubDomains
Links to (1)
- devos.no×1
Linked from (1)
- devos.no×1