nora.se
HTML metadata
Technology
- Stack
- Java
Third-party hosts loaded (1)
- cdn-eu.readspeaker.com×1
Social
Contact
- Phone
DNS records live
- NS
-
- dns01.dipcon.com
- dns02.ports.se
- dns03.ports.se
- dns04.ports.net
- MX
-
- 10 nora-se.mail.protection.outlook.com
- TXT
-
Show 7 TXT records
_fre6pmiwv5xfsr2mtwkwnf0mv791ov1_o9ncmyotsgpbf9wbmzvluf0fndo6z02kqhymbfgs88wvh96s7r15lvlff3cw8nfjhl3t3m94sqmxt3s633npsb7vjjw5ttylddhqwklssy4jj93slc0587yqzr7y975en1D1MIcZ/Cbtpo3Gs6o4K/uCjqUu/ApBxOkoVVUbtUG/pONx86HdXBPbYtk93DIDdetrsJKtNbCzK1UEA7e9g==5p41km51xw74xq46p97d6whybbdqcz4x
- Verified for
-
- Apple
- Microsoft 365
Email authentication partial
- SPF
-
v=spf1 mx a ip4:195.34.85.17/32 ip4:52.232.27.151/32 ip4:195.34.85.30/32 include:spf.protection.outlook.com include:_spf.ungapped.io include:mail.sitevision-cloud.net include:_se_net.axiell.com include:_uk.axiell.com include:all._spf.plma.se include:_spf.nanolearning.com include:sendgrid.net include:_spf.daladatorer.net ~allsoftfail (~all) · 11 DNS lookups (RFC limit is 10) - DMARC
-
v=DMARC1; p=none; sp=none; rua=mailto:it-nora@nora.se; ruf=mailto:it-nora@nora.se; rf=afrf; pct=100; ri=604800policy: none (monitoring only) · sp=none - DKIM
-
- selector2:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCkkdqITnQGPfn6FuTiE0TT5TuI4uNNEGwCuJsHIm5LN1hVmHkOk0W9TEc3VzqdQvTJNprorRRQe30G7TmQs3… - s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAtyOZuldDivEBmJPBnBunBWw8CnsFvW/yt2lxhFZxhihZ5WS7rR7fz7qpxDBSdp9+xWEkK8xKl4DxaC3OGR… - s2:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAls32tDsuA//mpHOFXYnYb1nKKSVQi9BJan5DAu2Lmz7RNqTYddXUPrpfOsjGQrm6qW6CZtV0OhHTKshUm0…
selectors probed - selector2:
Certificate (current)
R13
Expires in 78 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Permissions Policy
Header values
- referrer-policy
same-origin- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src 'self' *.readspeaker.com nora.tromanpublik.se recruit.visma.com *.kundo.se 'unsafe-inline' 'unsafe-eval'; font-src 'self' https: data:; img-src 'self' https: data:;- strict-transport-security
max-age=31536000; includeSubDomains; preload