martinservera.se
HTML metadata
Technology
- CMS
- Next.js
- Analytics
-
- Google Tag Manager
Third-party hosts loaded (1)
- www.googletagmanager.com×1
DNS records live
- NS
-
- a.portsdns.se
- b.portsdns.net
- MX
-
- 10 se.mx1.mailanyone.net
- 20 se.mx2.mx25.net
- 30 se.mx3.mailanyone.net
- 40 se.mx4.mx25.net
Email authentication strong
- SPF
-
v=spf1 include:spf.martinservera.se.eu-mzochpoa.e1.dspf.app -allstrict (-all) - DMARC
-
v=DMARC1; p=reject; rua=mailto:re+voa1tryaxkp@dmarc.postmarkapp.com,mailto:mzochpoa@rua.eu.dmarcmanager.app;policy: reject (enforced) - DKIM
-
- s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAr9wwJRU+fH5FWuOLDPErHeVMiiHKZunKDM/pVtlFmtlbcVZ9moM6a9fslKUIYNTONukIUxIzzwTTK6Y/ST… - s2:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAqswAmWIzHAd66wkprUr4fICXsbg3oOHKXhBrc1Rb/zhGfTuRYcBiK08wlSdyrUsnd0qdxgfbYida9ofr2q…
selectors probed - s1:
Certificates
Loading certificate
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Permissions Policy
Header values
- referrer-policy
origin-when-cross-origin- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src 'self'; script-src 'self' 'unsafe-inline' https://cdn.cookielaw.org https://www.googletagmanager.com *.datadoghq-browser-agent.com https://cdn.curator.io https://maps.googleapis.com https://web103.reachmee.com https://cdn.ontame.io *.cloudfront.net https://cdn.nowinteract.com https://*.kameleoon.io https://*.kameleoon.eu https://*.kameleoon.com https://*.kameleoon.net https://app.helphero.co https://helphero.co https://*.survicate.com https://*.survicate-cdn.com https://connect.facebook.net; connect-src 'self' *.martinservera.se *.browser-intake-datadoghq.eu https://browser-intake-datadoghq.eu *.google-analytics.com https://cdn.cookielaw.org https://geolocation.onetrust.com https://privacyportal-de.onetrust.com https://api.curator.io *.cloudfront.net https://maps.googleapis.com *.analytics.google.com https://imp2.nowinteract.com https://integration.algorecs.com/ https://*.kameleoon.io https://*.kameleoon.eu https://*.kameleoon.com https://*.kameleoon.net https://recs.algore- strict-transport-security
max-age=63072000; includeSubDomains; preload