juristforbundet.no
HTML metadata
Technology
- Server
- Microsoft-IIS
- ASP.NET
- 4.0.30319
- jQuery
- 3.1.1 known XSS (<3.5)
- Stack
- ASP.NET
- Analytics
-
- Google Tag Manager
Third-party hosts loaded (3)
- www.googletagmanager.com×2
- cdn-cookieyes.com×1
- dl.episerver.net×1
Contact
- Phone
DNS records live
- NS
-
- jamie.ns.cloudflare.com
- quentin.ns.cloudflare.com
- MX
-
- 0 dnmf-no.t-v1.mx.microsoft
- Verified for
-
- Dynamics 365
- GlobalSign
- Microsoft 365
Email authentication partial
- SPF
-
v=spf1 include:_spf.intility.com include:customers.clickdimensions.com include:emaileu.clickdimensions.com include:spf.protection.outlook.com -allstrict (-all) - DMARC
-
v=DMARC1; p=nonepolicy: none (monitoring only) - DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCkP4uSUKWt9pe7u9n2mFRQU7sM3lzQQiHZ1LRwIYwM+0EL0RHqt+TzHMHaXKT0D+FNgBgTgfCgtIPuXvQyPu… - selector2:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDrm5HNpVWucP0NJY4tksn/j+91S3R0SjMdZYq5UdVJYOCuuxxDsgDoznJfqzV1Z4vWE2MJJWicZq3/eNf+Q8…
selectors probed - selector1:
Certificate (current)
GlobalSign GCC R3 DV TLS CA 2020
Expires in 6 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy-report-only
- referrer-policy
- findings
-
- missing Content Security Policy
- missing frame protection
- missing content type protection
- missing Permissions Policy
Header values
- referrer-policy
strict-origin-when-cross-origin- strict-transport-security
max-age=31536000; includeSubDomains- content-security-policy-report-only
default-src 'self';script-src 'self' 'unsafe-inline' dl.episerver.net 'unsafe-eval' www.google-analytics.com www.googletagmanager.com cdn-cookieyes.com connect.facebook.com connect.facebook.net snap.licdn.com;style-src 'self' 'unsafe-inline';img-src 'self' www.google-analytics.com cdn-cookieyes.com www.facebook.com px.ads.linkedin.com www.googletagmanager.com connect.facebook.net;connect-src 'self' cdn-cookieyes.com log.cookieyes.com www.facebook.com www.googletagmanager.com px.ads.linkedin.com region1.google-analytics.com;frame-src 'self' www.youtube.com player.vimeo.com;