laesoe.dk
HTML metadata
Technology
Third-party hosts loaded (6)
- static.moliri.dk×16
- cdnjs.cloudflare.com×2
- cookiecontrol.bleau.dk×2
- cdn.jsdelivr.net×1
- cdn.moliri.dk×1
- moliricdn.azurewebsites.net×1
Social
Contact
- Phone
- Address
- Telefon:9621 3000kommunen@laesoe.dk
DNS records live
- NS
-
- ns.scannet2.dk
- ns2.scannet2.dk
- MX
-
- 10 laesoe-dk.mail.protection.outlook.com
- TXT
-
Show 5 TXT records
8g4dbhqrutt3ne7eqg1ckpcl6bn5tbu3vsmge5epsig1ge3mnh7asb48r2u7u60b0pk54es2mso26t1ark6mihqnj3q073f2bvrh98269laobmmluj5t191f30395guthl
- Verified for
-
- Apple
Email authentication strong
- SPF
-
v=spf1 include:_spf1050.spfprotect.com include:sendgrid.net include:_spf.emply.com -allstrict (-all) - DMARC
-
v=DMARC1; p=reject; rua=mailto:5f436d91ad419@dmarc.centerasecurity.com;policy: reject (enforced) - DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCdwWAJo6k8DCKySwWGh8H5zRseJm2RZgKKwxEqg/YqddKbq9rXgTdl2kzRnnAfQ4jArUlol3dERVnKPNBHTk…
selectors probed - selector1:
Certificate (current)
Go Daddy Secure Certificate Authority - G2
Expires in 126 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing frame protection
Header values
- referrer-policy
strict-origin-when-cross-origin- permissions-policy
accelerometer=(self), camera=(self), geolocation=(self), gyroscope=(self), magnetometer=(self), microphone=(self), payment=(self), usb=(self)- x-content-type-options
nosniff- content-security-policy
default-src 'self' fonts.gstatic.com fonts.googleapis.com static.moliri.dk *.azure.com *.google-analytics.com *.doubleclick.net data: www.gstatic.com statservicefunctions.azurewebsites.net hearingportalfilestorage.blob.core.windows.net cookiecontrol.bleau.dk *.devtunnels.ms api-eu1.cludo.com *.moliri.dk dawa.aws.dk cdn.jsdelivr.net cdnjs.cloudflare.com moliricdn.azurewebsites.net ;style-src 'self' 'unsafe-inline' fonts.googleapis.com cdhsign.dk cdnjs.cloudflare.com unpkg.com static.moliri.dk customer.cludo.com *.gstatic.com npmcdn.com moliricdn.azurewebsites.net ;script-src 'self' 'unsafe-inline' *.moliri.dk *.bleau.dk *.cludo.com *.gstatic.com *.monsido.com moliricdn.azurewebsites.net *.azure.com cdn.jsdelivr.net cookiecontrol.bleau.dk *.devtunnels.ms *.siteimproveanalytics.com dawa.aws.dk moliricdn.azurewebsites.net 'unsafe-eval';frame-ancestors https://localhost:44399 https://admin-dev.moliri.dk https://admin.moliri.dk https://admin-beta.moliri.dk https://localhost:5001 https://loc- strict-transport-security
max-age=31536000; includeSubDomains; preload