kro.se
HTML metadata
Technology
- Server
- nginx
- CMS
- Gatsby
- jQuery
- 1.12.4 known XSS (<3.5)
- Fonts
-
- Adobe Fonts
- Social widgets
-
- Vimeo Embed
Third-party hosts loaded (4)
- player.vimeo.com×2
- cdn.jsdelivr.net×1
- cloud.typenetwork.com×1
- use.typekit.net×1
Social
DNS records live
- NS
-
- ns1.namesystem.se
- ns2.namesystem.se
- ns3.namesystem.se
- MX
-
- 10 mx01.glesys.se
- 20 mx02.glesys.se
Email authentication partial
- SPF
-
v=spf1 include:email.prnewswire.com include:spf.multinet.com include:spf.glesys.se -all include:all._spf.plma.se ~all include:spf.multinet.com ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=none;policy: none (monitoring only) - DKIM
-
- s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA22iSi8bohTdfdgPgYgwiUKe+BKBM37Rtfuh7eKDXeOTfyvpjmWMEFiZK4ulmhefQ81M0j474m7uBSxf5CY… - s2:
k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDfh7NZNbvhXzYbxb/xnBDzp5NJbaqbcslD+MwmiTFeJXdYGUeowbACsv5MzJ92YfL+PjSjMdNCkQKvdBCQEiXzYc…
selectors probed - s1:
Certificate (current)
R13
Expires in 82 days
HTTP security headers
- present
-
- x-frame-options
- x-content-type-options
- referrer-policy
- cross-origin-opener-policy
- findings
-
- missing HSTS
- missing Content Security Policy
- missing Permissions Policy
Header values
- referrer-policy
same-origin, origin-when-cross-origin- x-frame-options
DENY- x-content-type-options
nosniff- cross-origin-opener-policy
same-origin