kbab.se
HTML metadata
Technology
- JS framework
- React
- Stack
- Java
Third-party hosts loaded (1)
- karlstad.imagevault.app×1
Social
DNS records live
- NS
-
- a.dns.tele2.net
- b.dns.tele2.net
- c.dns.tele2.net
- dns1.karlstad.se
- dns2.karlstad.se
- MX
-
- 10 kbab-se.mail.protection.outlook.com
- TXT
-
bLLPsphs67dYjpBsmNGg/PwDl1QMIhflaTK2QCC7BBb2NdXZULdu/cL58DmwcqDCmMhd5u93yJflbrNcgJQAWA==hes=60dbf8cf9140f7d7168284aabb3e0afe
- Verified for
-
- GlobalSign
- Microsoft 365
Email authentication partial
- SPF
-
v=spf1 include:spf.protection.outlook.com -allstrict (-all) - DMARC
-
v=DMARC1;p=nonepolicy: none (monitoring only) - DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAuMF0xOISOpGh8BpC08Rr2n7WBbf1dQMlZBESB4Tt4c6eW8tdbofqfG4LasFAPZ+vQclCTHMDMauGWq…
selectors probed - selector1:
Certificate (current)
R12
Expires in 54 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- missing Permissions Policy
Header values
- referrer-policy
no-referrer- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src 'none'; script-src 'self' 'nonce-8dadda00-5d94-11f1-86bf-e5627687b594' 'unsafe-eval' https://uistats.sitevision.se/ https://www.browsealoud.com/ https://karlstad.containers.piwik.pro/ https://www.netpublicator.com/ https://export.objektvision.se/ https://svanalytics.piwik.pro/ https://svanalytics.containers.piwik.pro/; img-src 'self' https://images.unsplash.com https://karlstad.se https://i.ytimg.com/ https://karlstad.imagevault.app/ https://static.netpublicator.com/; connect-src 'self' https://plus.browsealoud.com https://uistats.sitevision.se https://www.browsealoud.com https://youtube.com https://karlstadskommunonline.sharepoint.com/ https://karlstad.piwik.pro/ https://svanalytics.piwik.pro/ https://svanalytics.containers.piwik.pro/; style-src 'self' 'unsafe-inline' https://karlstad.imagevault.app/; object-src 'none' ; base-uri 'self'; font-src 'self'; frame-src 'self' https://www.youtube.com/ https://youtube.com/ https://export.objektvision.se/ https://marknad.kbab.se/- strict-transport-security
max-age=31536000; includeSubDomains; preload