inet.fi
HTML metadata
Technology
- CMS
- Next.js
Contact
- Phone
DNS records live
- NS
-
- ns1-fin.global.sonera.fi
- ns1-swe.global.sonera.se
- ns2-fin.global.sonera.fi
- ns2-usa.global.sonera.net
- MX
-
- 10 mail.cm.telia.net
- Verified for
-
Email authentication strong
- SPF
-
v=spf1 ip4:81.236.57.0/24 ip4:81.227.116.64/26 ip4:80.74.205.14 ip4:195.165.144.43 ip4:80.74.207.112/28 ip4:192.89.123.25 ip4:62.71.179.0/24 ip4:81.224.166.0/24 ip4:193.211.41.131 include:spf.mailcore.net ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=reject; ruf=mailto:postmaster@pp.inet.fi; fo=1policy: reject (enforced) - DKIM
-
- s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAuewloTleGcsOOwQpyHOjPH+KA+j02TtkshbKSGY4nU58rfA06qhucwFj7aEdZnVkSZzt6ljLIxpRlevCJz… - s2:
k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQC3sbld96/HRHdtKTgQCFSPENcXvoyN7Ybi5cCbSTFeMs/m+kcpFxHb4bTBJzvEua9bq3nlE65K7dxcxsqmtMqAiQ…
selectors probed - s1:
Certificate (current)
R13
Expires in 31 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- cross-origin-opener-policy
- cross-origin-embedder-policy
- cross-origin-resource-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Permissions Policy
Header values
- referrer-policy
same-origin- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src 'self'; base-uri 'self'; frame-ancestors 'self'; form-action 'self'; style-src 'self' https://hcaptcha.com https://*.hcaptcha.com; style-src-elem 'self' 'unsafe-inline'; style-src-attr 'self' 'unsafe-inline'; script-src 'self' 'unsafe-inline' https://hcaptcha.com https://*.hcaptcha.com https://js.stripe.com; frame-src 'self' https://hcaptcha.com https://*.hcaptcha.com https://js.stripe.com; img-src 'self' 'unsafe-inline' 'unsafe-eval' https://js.stripe.com https://strapi.inbox.com; connect-src 'self' https://hcaptcha.com https://*.hcaptcha.com https://*.fjordmail.no https://*.recurrent.no;- strict-transport-security
max-age=31536000; includeSubDomains; preload- cross-origin-opener-policy
same-origin- cross-origin-embedder-policy
unsafe-none- cross-origin-resource-policy
same-origin