muuttomaailma.fi
HTML metadata
Technology
- CDN
- Amazon CloudFront
- Server
- Apache
- CMS
- WordPress
- jQuery
- 1.12.4 known XSS (<3.5)
- Analytics
-
- Google Tag Manager
- Fonts
-
- Google Fonts
Third-party hosts loaded (3)
- ajax.googleapis.com×2
- fonts.googleapis.com×1
- www.googletagmanager.com×1
DNS records live
- NS
-
- ns-1082.awsdns-07.org
- ns-1589.awsdns-06.co.uk
- ns-546.awsdns-04.net
- ns-8.awsdns-01.com
- MX
-
- 0 muuttomaailma-fi.mail.protection.outlook.com
- TXT
-
mandrill_verify.xeKMDy4zZHf6eyPtrdcxjw
- Verified for
-
- Microsoft 365
Email authentication partial
- SPF
-
v=spf1 include:_spf.mlsend.com include:_spf.mailersend.net a:muuttomaailma.fi include:spf.protection.outlook.com include:servers.mcsv.net include:spf.mandrillapp.com include:mail.zendesk.com -allstrict (-all) - DMARC
-
v=DMARC1; p=none;policy: none (monitoring only) - DKIM
-
- k1:
k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDbNrX2cY/GUKIFx2G/1I00ftdAj713WP9AQ1xir85i89sA2guU0ta4UX1Xzm06XIU6iBP41VwmPwBGRNofhBVR+e6WHUo…
selectors probed - k1:
Certificate (current)
Amazon RSA 2048 M04
Expires in 78 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- short HSTS max-age
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Permissions Policy
Header values
- referrer-policy
no-referrer-when-downgrade- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src 'self' 'unsafe-inline' 'unsafe-eval' data: https://alma-app-conf.s3.eu-west-1.amazonaws.com/ https://cdn.privacy-mgmt.com https://*.muuttomaailma.fi https://*.muuttomaailma.com *.kilpailutamuuttopalvelu.fi https://*.facebook.com https://*.facebook.net https://*.zopim.com wss://*.zopim.com https://*.gravatar.com https://*.gstatic.com https://*.googleapis.com https://*.google-analytics.com https://*.analytics.google.com https://*.optimonk.com https://*.g.doubleclick.net https://www.google.com https://www.google.fi https://*.bing.com https://*.adnxs.com https://www.googletagmanager.com https://www.googleadservices.com https://*.googlesyndication.com https://adservice.google.fi https://adservice.google.com https://*.krxd.net https://s3.amazonaws.com https://www.youtube-nocookie.com https://*.adform.net https://c.bannerflow.net https://servedby.revive-adserver.net https://maxcdn.bootstrapcdn.com https://*.ensighten.com https://tagmanager.google.com https://*.gravito.net https://- strict-transport-security
max-age=2592000; includeSubDomains