nesslink.fi

.fi crawl

First seen 2026-06-01 · Last seen 2026-06-01 · ok HTTP/1.1 200 405 ms crawled 2026-06-02

FI · 95.217.13.53 · AS24940 Hetzner Online GmbH

Reputation 92/100 no dmarc policy

Classifying

HTML metadata

Title
Maj ja Tor Nesslingin säätiö
Language
en

Technology

Server
nginx
Fonts
  • Google Fonts

Third-party hosts loaded (2)

  • fonts.googleapis.com×2
  • fonts.gstatic.com×1

DNS records live

NS
  • ns1.shellit.org
  • ns2.shellit.org
  • ns3.shellit.org
MX
  • 10 mail1.shellit.org
  • 50 mail2.shellit.org

Email authentication weak

SPF
v=spf1 include:spf.shellit.org ~all
softfail (~all)
DMARC
not published
DKIM
no key found at common selectors

Certificate (current)

E8
from 2026-05-05 to 2026-08-03
Expires in 59 days

HTTP security headers

Header hygiene 80/100 Checked live page: https://nesslink.fi/

present
  • strict-transport-security
  • content-security-policy
  • x-frame-options
  • x-content-type-options
findings
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
  • missing Referrer Policy
  • missing Permissions Policy
Header values
x-frame-options
DENY
x-content-type-options
nosniff
content-security-policy
default-src 'none'; connect-src 'self'; object-src 'self'; font-src 'self' https://fonts.gstatic.com; form-action 'self' *.rimbert.fi *.signicat.com *.nets.eu *.stockholm.se *.stockholm *.telia.fi *.op.fi *.danskebank.com *.saastopankki.fi *.aktia.fi *.omasp.fi *.poppankki.fi *.s-pankki.fi *.handelsbanken.fi *.alandsbanken.fi *.nordea.com *.kulturfonden.fi idp.shh.fi idp.hanken.fi *.goteborg.se; img-src 'self' data: *.rimbert.fi; script-src 'self'; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com
strict-transport-security
max-age=63072000; includeSubdomains; preload

Linked from (1)