nordeanode.se
HTML metadata
Technology
- CMS
- Next.js
Third-party hosts loaded (1)
- widget.trustpilot.com×1
Contact
- Phone
DNS records live
- NS
-
- ns0.nordea.com
- ns1.nordea.com
- ns2.nordea.com
- spdns3.cscdns.net
- MX
-
- 1 aspmx.l.google.com
- 10 alt3.aspmx.l.google.com
- 10 alt4.aspmx.l.google.com
- 5 alt1.aspmx.l.google.com
- 5 alt2.aspmx.l.google.com
- TXT
-
MS=20307359
- Verified for
-
- Atlassian
- Cursor
Email authentication strong
- SPF
-
v=spf1 include:_spf.google.com include:spf.mailjet.com ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=reject; fo=1; ri=3600; rua=mailto:nordea@rua.agari.com; ruf=mailto:nordea@ruf.agari.compolicy: reject (enforced) - DKIM
-
- google:
v=DKIM1;k=rsa;p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA5ivL2eR7m6aLYS7fqNZMafNjysu5WWErE4Yuy4wklDXuVfhl1jDGI64YUPOuzH8YrxVTkoZF5zVLDFQR…
selectors probed - google:
Certificate (current)
WR3
Expires in 40 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
sameorigin- permissions-policy
accelerometer=(), ambient-light-sensor=(), autoplay=(), battery=(), camera=(), cross-origin-isolated=(), display-capture=(), document-domain=(), encrypted-media=(), execution-while-not-rendered=(), execution-while-out-of-viewport=(), fullscreen=(self), geolocation=(), gyroscope=(), keyboard-map=(), magnetometer=(), microphone=(), midi=(), navigation-override=(), payment=(), picture-in-picture=(), publickey-credentials-get=(), screen-wake-lock=(), sync-xhr=(), usb=(), web-share=(), xr-spatial-tracking=()- x-content-type-options
nosniff- content-security-policy
default-src 'self' ; img-src 'self' data: blob: *.storage.googleapis.com https://storage.googleapis.com *.google-analytics.com *.analytics.google.com https://nordeanode.se https://www.google.com/ads/ga-audiences https://www.google.se/ads/ https://www.google.com/pagead/ https://www.google.se/pagead/ https://images.ctfassets.net/ https://www.googletagmanager.com https://translate.google.com ; font-src 'self' https://advinans-static-resources.storage.googleapis.com https://fonts.googleapis.com https://fonts.gstatic.com/ ; style-src 'self' 'unsafe-inline' https://advinans-static-resources.storage.googleapis.com https://fonts.googleapis.com https://fonts.gstatic.com/ ; style-src-elem 'self' 'unsafe-inline' https://advinans-static-resources.storage.googleapis.com https://fonts.googleapis.com/ ; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://www.googletagmanager.com https://www.googleadservices.com https://www.google-analytics.com/analytics.js https://widget.trustpilot.com/bootstrap/- strict-transport-security
max-age=31536000; includeSubDomains; preload