huima.com
HTML metadata
Technology
- Server
- nginx
- CMS
- Joomla
- Analytics
-
- Google Tag Manager
Third-party hosts loaded (1)
- www.googletagmanager.com×1
Social
Contact
- Address
- Asemakuja 2, 32700, Huittinen
Registration
- Registrar
- Realtime Register B.V.
- Created
- 1999-12-02
- Expires
- 2027-12-02 549 days left
- Updated
- 2026-04-28
- Name servers
-
- dns1.web1.fi
- dns2.web1.fi
- dns3.web1.fi
DNS records live
- NS
-
- dns1.web1.fi
- dns2.web1.fi
- dns3.web1.fi
- MX
-
- 0 aspmx.l.google.com
- 10 alt3.aspmx.l.google.com
- 10 alt4.aspmx.l.google.com
- 5 alt1.aspmx.l.google.com
- 5 alt2.aspmx.l.google.com
- Verified for
-
- Microsoft 365
Email authentication partial
- SPF
-
v=spf1 mx include:_spf.google.com include:servers.mcsv.net include:sendersrv.com include:spf.systec.fi a:auth-smtp.kotisivut.com ip4:81.22.248.0/25 ip4:62.44.193.28 ip4:62.44.193.26 ~allsoftfail (~all) - DMARC
-
v=DMARC1;p=none;rua=mailto:webmaster@huima.compolicy: none (monitoring only) - DKIM
-
- k2:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAv2aC2KjGKLOwTweBY5A9RpjsxaBXR9r7OAU6U8/zn92ivImI75naUujWbItRI/QmL1jy5PWGqLwoUA…
selectors probed - k2:
Certificate (current)
R13
Expires in 55 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing content type protection
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
SAMEORIGIN- content-security-policy
default-src 'self'; img-src 'self' data: *.lfeeder.com *.google-analytics.com cdn.jsdelivr.net/emojione/ *.google.com *.google.fi *.googletagmanager.com *.googleadservices.com *.googlesyndication.com *.g.doubleclick.net *.facebook.com *.linkedin.com; font-src 'self' fonts.gstatic.com; frame-src td.doubleclick.net *.googletagmanager.com; style-src 'self' 'unsafe-inline'; script-src 'self' 'nonce-huima-js-6a1a7c7d95187-references-src' 'nonce-huima-js-6a1a7c7d95189-cta-src'; script-src-elem 'self' 'unsafe-inline' *.huima.com *.googletagmanager.com sc.lfeeder.com cdn.jsdelivr.net connect.facebook.net *.g.doubleclick.net *.googleadservices.com *.googlesyndication.com snap.licdn.com *.clarity.ms ; connect-src 'self' *.huima.com *.google-analytics.com *.google.com *.google.fi *.g.doubleclick.net *.googleadservices.com *.googlesyndication.com px.ads.linkedin.com *.clarity.ms- strict-transport-security
max-age=31536000