lantero.se
HTML metadata
Technology
- Server
- nginx
- CMS
- Next.js
- JS framework
- Next.js
- Analytics
-
- Google Tag Manager
Third-party hosts loaded (2)
- objects.dc-sto1.glesys.net×4
- www.googletagmanager.com×1
Social
Contact
- Phone
- Address
- Drottninggatan 71C111 36 Stockholm
DNS records live
- NS
-
- ns1.loopia.se
- ns2.loopia.se
- MX
-
- 1 lantero-se.mail.protection.outlook.com
- TXT
-
detectify-verification=8f1335146ea94091025a118e0e60e37d_3z0meisfsuxdsipod0kzlnjfa7sco5x_uudfd9l1yzcth1i34ru5nvirsspnf7g
- Verified for
-
- Microsoft 365
Email authentication weak
- SPF
-
v=spf1 include:kundspf.loopia.se include:spf.protection.outlook.com include:one.zoho.com -allstrict (-all) - DMARC
- not published
- DKIM
- no key found at common selectors
Certificate (current)
E7
Expires in 38 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
DENY- permissions-policy
camera=(), microphone=(), geolocation=(), payment=(), usb=(), serial=(), bluetooth=(), magnetometer=(), autoplay=(self "https://*.youtube.com" "https://youtu.be"), encrypted-media=(self "https://*.youtube.com" "https://youtu.be"), fullscreen=(self "https://*.youtube.com" "https://youtu.be"), picture-in-picture=(self "https://*.youtube.com" "https://youtu.be"), accelerometer=(self "https://*.youtube.com" "https://youtu.be"), gyroscope=(self "https://*.youtube.com" "https://youtu.be"), clipboard-write=(self "https://*.youtube.com" "https://youtu.be" "https://*.ytimg.com" "https://play.google.com"), display-capture=(self)- x-content-type-options
nosniff- content-security-policy
default-src 'self'; base-uri 'self'; form-action 'self'; script-src 'self' 'unsafe-inline' *.cookiebot.com *.cookiebot.eu *.usercentrics.eu *.hcaptcha.com hcaptcha.com *.googletagmanager.com *.google-analytics.com *.analytics.google.com *.googleadservices.com *.g.doubleclick.net pagead2.googlesyndication.com *.google.com *.google.se *.google.de *.google.fr *.google.co.uk *.google.es *.google.it *.google.nl fonts.google.com apis.google.com translate.googleapis.com www.gstatic.com td.doubleclick.net *.youtube.com youtu.be *.ytimg.com play.google.com calendly.com *.calendly.com challenges.cloudflare.com; frame-src 'self' *.cookiebot.com *.cookiebot.eu *.usercentrics.eu *.hcaptcha.com hcaptcha.com *.googletagmanager.com *.google-analytics.com *.analytics.google.com *.googleadservices.com *.g.doubleclick.net pagead2.googlesyndication.com *.google.com *.google.se *.google.de *.google.fr *.google.co.uk *.google.es *.google.it *.google.nl fonts.google.com apis.google.com translate.googleapis.c- strict-transport-security
max-age=15724800; includeSubdomains
Links to (28)
- youtube.com×1
- youtu.be×1
- x.com×1
- vindex.se×1
- vespergroup.se×1
- trafikverket.se×1
- spotify.com×1
- soltechenergy.com×1
- sigtuna.se×1
- sef.se×1
- norrbotten.se×1
- nordicwellness.se×1
- luleaenergi.se×1
- lulea.se×1
- ljungsjoberg.se×1
- linkedin.com×1
- kommunal.se×1
- kjell.com×1
- instagram.com×1
- huddinge.se×1
- glesys.net×1
- gavle.se×1
- fi.se×1
- cancerfonden.se×1
- cabonlinegroup.com×1
- botkyrka.se×1
- barncancerfonden.se×1
- attendo.se×1