nesslink.fi
HTML metadata
Technology
- Server
- nginx
- Fonts
-
- Google Fonts
Third-party hosts loaded (2)
- fonts.googleapis.com×2
- fonts.gstatic.com×1
DNS records live
- NS
-
- ns1.shellit.org
- ns2.shellit.org
- ns3.shellit.org
- MX
-
- 10 mail1.shellit.org
- 50 mail2.shellit.org
Email authentication weak
- SPF
-
v=spf1 include:spf.shellit.org ~allsoftfail (~all) - DMARC
- not published
- DKIM
- no key found at common selectors
Certificate (current)
E8
Expires in 59 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
DENY- x-content-type-options
nosniff- content-security-policy
default-src 'none'; connect-src 'self'; object-src 'self'; font-src 'self' https://fonts.gstatic.com; form-action 'self' *.rimbert.fi *.signicat.com *.nets.eu *.stockholm.se *.stockholm *.telia.fi *.op.fi *.danskebank.com *.saastopankki.fi *.aktia.fi *.omasp.fi *.poppankki.fi *.s-pankki.fi *.handelsbanken.fi *.alandsbanken.fi *.nordea.com *.kulturfonden.fi idp.shh.fi idp.hanken.fi *.goteborg.se; img-src 'self' data: *.rimbert.fi; script-src 'self'; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com- strict-transport-security
max-age=63072000; includeSubdomains; preload