mykid.no
HTML metadata
Technology
- Server
- nginx
- Fonts
-
- Google Fonts
- Social widgets
-
- Vimeo Embed
Third-party hosts loaded (3)
- fonts.googleapis.com×1
- fonts.gstatic.com×1
- player.vimeo.com×1
Social
Contact
DNS records live
- NS
-
- addilyn.ns.cloudflare.com
- morgan.ns.cloudflare.com
- MX
-
- 0 spamfilter.nordichosting.com
- Verified for
-
Email authentication strong
- SPF
-
v=spf1 include:spf.nordic.hosting include:spf.mykid.no -allstrict (-all) - DMARC
-
v=DMARC1; p=reject; aspf=s; rua=mailto:d53bbc28a702430ea811578e869316ce@dmarc-reports.cloudflare.net;policy: reject (enforced) - DKIM
-
- default:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA+ycq5HHWxykKMnT9FhC6IKsiKMAl2KpHKDMAt9zbaOcVo87MJoPQN1RAW8lt1SOPAEK5rJ/xFHiFcS…
selectors probed - default:
Certificate (current)
GoGetSSL RSA DV CA
Expires in 222 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
origin-when-cross-origin- x-frame-options
SAMEORIGIN- permissions-policy
fullscreen=(), geolocation=()- x-content-type-options
nosniff- content-security-policy
default-src *; script-src 'self' 'unsafe-inline' 'unsafe-eval' mykid.no www.gstatic.com maps.googleapis.com backstage.mykid.no; img-src * blob: data:; style-src 'self' 'unsafe-inline' fonts.gstatic.com www.gstatic.com fonts.googleapis.com; font-src 'self' fonts.gstatic.com fonts.googleapis.com data:; form-action 'self'; report-uri https://hosting.guru/csp-report/report.php- strict-transport-security
max-age=63072000; includeSubDomains
Links to (5)
- linkedin.com×1
- google.com×1
- facebook.com×1
- bsky.app×1
- apple.com×1