karistelefon.fi
HTML metadata
Technology
- Server
- Apache
- CMS
- Joomla
- Analytics
-
- Google Tag Manager
- Cookie consent
-
- Cookiebot
Third-party hosts loaded (4)
- consent.cookiebot.com×1
- files.jquest.fi×1
- widget.trustmary.com×1
- www.googletagmanager.com×1
Social
Contact
- Phone
Registration
- Created
- 2000-10-17
- Name servers
-
- dns1.sydweb.fi [94.237.8.205] [2a04:3545:1000:720:3c8b:56ff:fe3d:13a2] [ok]
- dns4.sydweb.fi [80.69.173.18] [2a04:3540:1000:310:3c8b:56ff:fe3d:5a2c] [ok]
- dns3.sydweb.fi [37.27.29.28] [2a01:4f9:c012:1f99::1] [ok]
DNS records live
- NS
-
- dns1.sydweb.fi
- dns3.sydweb.fi
- dns4.sydweb.fi
- MX
-
- 10 web05.sydweb.fi
- TXT
-
k2967pbb41ndhkts4q1lu83j24
Email authentication weak
- SPF
-
v=spf1 ip4:94.237.36.39 +mx +a +a:mail.sydweb.fi +a:extra.karistelefon.fi +ip4:82.197.31.32/28 a:smtp.ktnet.fi ~allsoftfail (~all) - DMARC
- not published
- DKIM
-
- default:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAszEwMzee3S762dCPFbht8cbxhHioMhJOPloI0wDYeiWNzg9oxBw+XGtfehbm71oqmcqDEfkklcqIsB…
selectors probed - default:
Certificate (current)
Go Daddy Secure Certificate Authority - G2
Expires in 53 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy-report-only
- x-frame-options
- x-content-type-options
- referrer-policy
- cross-origin-opener-policy
- findings
-
- missing Content Security Policy
- weak frame protection
- missing Permissions Policy
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN, SAMEORIGIN- x-content-type-options
nosniff- strict-transport-security
max-age=63072000; includeSubDomains; preload- cross-origin-opener-policy
same-origin- content-security-policy-report-only
default-src 'none'; manifest-src 'self'; media-src 'self'; frame-src 'self' www.youtube.com youtu.be service.giosg.com www.facebook.com 5963.clients.giosgusercontent.com www.google.com www.googletagmanager.com webforms.pipedrive.com td.doubleclick.net consentcdn.cookiebot.com; style-src 'self' fonts.googleapis.com 'unsafe-inline' service.giosg.com files.jquest.fi use.typekit.net p.typekit.net; script-src 'self' 'unsafe-eval' 'unsafe-inline' widget.trustmary.io update.sydweb.fi www.google-analytics.com www.googletagmanager.com service.giosg.com www.googleadservices.com use.typekit.net connect.facebook.net www.google.com www.gstatic.com *.interactions.giosgusercontent.com api.giosg.com maps.googleapis.com webforms.pipedrive.com *.pipedriveassets.com consentcdn.cookiebot.com consent.cookiebot.com files.jquest.fi; font-src 'self' fonts.gstatic.com use.typekit.net giosg-chat-public-eu.s3.amazonaws.com; img-src 'self' data: *.tile.openstreetmap.org www.google-analytics.com www.google.com www