mariacasino.se
HTML metadata
Technology
- Server
- kindred-loadbalancer
Contact
DNS records live
- NS
-
- dns-ext1.northdev.net
- dns-ext2.northdev.net
- emea.excedodns.eu
- global.excedodns.com
- sto.excedodns.se
- world.excedodns.org
- MX
-
- 10 webmail.parabol.com
- TXT
-
Show 6 TXT records
1483012e-d8d3-4749-9296-b82f83b10e81427689a1-c2b8-4658-ada9-9e64ad2f4dc996c78c2c-e20e-49a8-8c6b-9f9c87a27ddfacb68f8c-e457-4f5a-b854-78f5a5220b1bdee96dc0-3897-4517-b22d-10c815e7f81cf6cd5309-0bfd-4fe1-987c-05c3b4184578
- Verified for
-
- Meta
- Microsoft 365
Email authentication weak
- SPF
- not published
- DMARC
-
v=DMARC1;p=none;sp=none;aspf=r;adkim=r;pct=100;rua=mailto:dmarc@mariacasino.com;ruf=mailto:dmarc@mariacasino.com; fo=1policy: none (monitoring only) · sp=none - DKIM
- no key found at common selectors
Certificate (current)
R13
Expires in 30 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- cross-origin-opener-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src 'none';script-src 'nonce-7c061957-8fdd-4643-b479-29025b4bd80e' 'strict-dynamic' 'unsafe-eval' 'unsafe-inline' 'report-sample';font-src 'self' https: data:;style-src 'self' https: 'unsafe-inline' 'report-sample';img-src https: data: blob:;connect-src 'self' https: wss:;base-uri 'self';worker-src 'self' blob:;manifest-src 'self';frame-ancestors 'self' https://*.mariacasino.se https://kindredgroup.custhelp.com/ https://*.kindredtech.net/ https://*.kindredgroup.com/;media-src * blob:;frame-src https: jockey:;report-uri https://www.mariacasino.se/eum-collector/report/csp-report;- strict-transport-security
max-age=63072000; includeSubDomains; preload- cross-origin-opener-policy
same-origin-allow-popups