modity.se

.se crawl

First seen 2026-05-30 · Last seen 2026-05-31 · ok HTTP/1.1 200 615 ms crawled 2026-05-31

SE · 193.183.80.13 · AS204074 Nordisk Media Utveckling AB

Reputation 95/100 weak security headers

Classifying

HTML metadata

Title
Modity
Description
Public webpage for Modity Energy Trading AB
Language
sv

Technology

CMS
Next.js

Third-party hosts loaded (1)

  • images.ctfassets.net×11

DNS records live

NS
  • ephemera.nmugroup.se
  • ns-any1.nmugroup.se
  • ns-any2.nmugroup.se
  • origo.nmugroup.com
  • unit.nmugroup.com
  • vertex.nmugroup.se
MX
  • 0 modity-se.mail.protection.outlook.com
TXT
  • u6rh5p4omi7gkuap5j3nqulnn7
  • /dyH8QIUgWmcQPMkdDmCLIyHVkKRC1Z8WgOMPi4PHjA=
Verified for
  • Anthropic
  • Apple
  • Atlassian
  • GlobalSign
  • Google
  • Microsoft 365

Email authentication strong

SPF
v=spf1 include:spf.protection.outlook.com ip4:193.181.45.220 ip4:193.235.149.145 include:_spf.anpdm.com -all
strict (-all)
DMARC
v=DMARC1; p=reject; aspf=s; rua=mailto:rua.reports@modity.se
policy: reject (enforced)
DKIM
  • selector2: v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDXnTEOacEvhC9N94ao0CuiRRGcwtRAYaEpZ1r+AeEeRe0ZCWGqNe/0Tf7Vm7MZANX37EG5XAeRIhelqWQmvA…
selectors probed

Certificate (current)

E8
from 2026-05-05 to 2026-08-03
Expires in 63 days

HTTP security headers

Header hygiene 40/100 Checked live page: https://www.modity.se/sv

present
  • content-security-policy
findings
  • missing HSTS
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
  • missing frame protection
  • missing content type protection
  • missing Referrer Policy
  • missing Permissions Policy
Header values
content-security-policy
default-src 'self' cdn.contentful.com videos.ctfassets.net *.vault.azure.net *.clarity.ms https://www.clarity.ms https://c.bing.com https://*.in.applicationinsights.azure.com *.altcha.org; connect-src 'self' https://*.in.applicationinsights.azure.com https://js.monitor.azure.com/ *.clarity.ms *.altcha.org; script-src 'self' 'unsafe-eval' 'unsafe-inline' *.clarity.ms; worker-src 'self' blob:; style-src 'self' 'unsafe-inline'; img-src 'self' blob: data: cdn.contentful.com images.ctfassets.net videos.ctfassets.net *.openstreetmap.org downloads.ctfassets.net *.clarity.ms c.bing.com; font-src 'self' cdn.contentful.com eu.altcha.org; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'none'; upgrade-insecure-requests;

Links to (1)

Linked from (1)