nordeapension.dk
HTML metadata
Technology
- CMS
- Gatsby
- jQuery
- 3.7.1
- Stack
- Java
Third-party hosts loaded (2)
- js.monitor.azure.com×1
- policy.app.cookieinformation.com×1
Contact
- Address
- Grønjordsvej 10, 2300, København S, DK
DNS records live
- NS
-
- ns0.nordea.com
- ns1.nordea.com
- ns2.nordea.com
- spdns3.cscdns.net
- MX
-
- 0 nordeapension-dk.mail.protection.outlook.com
- Verified for
-
- Microsoft 365
Email authentication strong
- SPF
-
v=spf1 include:spf.protection.outlook.com include:carmamail.com include:_spf.salesforce.com ip4:77.66.23.122 ip4:185.158.63.109 -allstrict (-all) - DMARC
-
v=DMARC1; p=reject; rua=mailto:DMARC-NP@nordeapension.dk; ruf=mailto:DMARC-NP-fail@nordeapension.dk; fo=1policy: reject (enforced) - DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA0ZypWCrRc8uVuCS6KuMSRZ4u9+izcQO03mwJn6/UKe5/p0WNtRE7NfsW5p2A6YLJGUa5fLdXKUj946… - s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAtaUx5qVQ+kJaXSfwS5exiL/KhRGNTjQIbvXdtU04OsNcVdh2aViiPlanXewbV+cnCTiFdut4Usmfr6RfHX… - s2:
k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDVsBQl+kYeiwJBHeggjXYyGOz+GAVikFRZ292bXmkp4vC96kqp6Vq7U8UsLjTDFZqQUHOJNbrXRIFVrWWWhyEORd…
selectors probed - selector1:
Certificate (current)
Entrust OV TLS Issuing RSA CA 1
Expires in 22 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- findings
-
- short HSTS max-age
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- weak frame protection
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
ALLOW-FROM https://design-<xxx>.ci360.sas.com- x-content-type-options
nosniff- content-security-policy
script-src 'self' 'unsafe-inline' 'unsafe-eval' blob: *.nordeapension.dk https://www.googletagmanager.com *.googletagmanager.com *.cookieinformation.com https://dev.visualwebsiteoptimizer.com *.visualwebsiteoptimizer.com *.imgeng.in *.google.dk *.google.se *.google.no *.google.nl *.google.gl *.google.gr *.google.pl *.google.iq www.google.com www.google-analytics.com https://www.google-analytics.com www.facebook.com widget.trustpilot.com *.doubleclick.net https://connect.facebook.net https://www.googleadservices.com www.googleadservices.com trustpilot.com *.danid.dk cdnjs.cloudflare.com https://polyfill.io www.youtube.com *.monitor.azure.com *.ditonlinebetalingssystem.dk *.dawa.aws.dk *.scalepoint.com www.talenthub.io https://talenthub.io https://s3-eu-central-1.amazonaws.com/talenthub.io *.googleapis.com *.form.io https://app.vwo.com https://cdn.jsdelivr.net https://via.ritzau.dk https://leadvalidator.dk; frame-ancestors 'self' *.ci360.sas.com nordeapension.ankiro.dk;- strict-transport-security
max-age=600; includeSubDomains; preload