norraskog.se
HTML metadata
Technology
- Analytics
-
- Google Analytics
- Google Tag Manager
Third-party hosts loaded (4)
- cdn.cookietractor.com×2
- js.monitor.azure.com×1
- www.google-analytics.com×1
- www.googletagmanager.com×1
Social
Contact
- Phone
DNS records live
- NS
-
- dns1.zaccodigitaltrustlabs.com
- dns2.zaccodigitaltrustlabs.net
- dns3.zaccodigitaltrustlabs.se
- dns4.zaccodigitaltrustlabs.se
- ns1.zaccodns.com
- ns2.zaccodns.se
- MX
-
- 10 norraskog-se.mail.protection.outlook.com
- TXT
-
Show 4 TXT records
_sr1n1myynlluhnzedz80fsuq9llexra_apqdm3816nhovv7m02lrg1eztzdb2h5vSoS_f24e04fd55694339332ac025_ma6v5ejaqq0dllkk33e63xvgto1yy16
- Verified for
-
- Apple
- GlobalSign
- Microsoft
- Microsoft 365
Email authentication strong
- SPF
-
v=spf1 include:spf.protection.outlook.com include:spf.jetshop.se include:_spf.netigate.se -allstrict (-all) - DMARC
-
v=DMARC1; p=quarantine; rua=mailto:72wc3mxk@ag.eu.dmarcadvisor.com,mailto:dmarc_rua@lets-secure.eu;policy: quarantine - DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAwIFMcMwGfgjRkUQn3PbTHiZlwXyLhSIq2gcGDNDN+bY7xBL5dv1e7cBktDmcN9B1vNIvLhLzEWcOyu… - s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAsjSgSnTTa+hvvT4mRNejQpGuqPYUIfS1b2pmpDm6C39MmD7sfhAu5+aITQjZ2JosAlYw66sdiPwkFNQXwW… - s2:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAqZ32LQkIoNslp8hnip55bt91/yT7hbyqMEGQweNpo8R8gdZ23ZCbVvY0VUQwblQvvjbdCHSyVfFJW+B8od…
selectors probed - selector1:
Certificate (current)
GeoTrust TLS RSA CA G1
Expires in 74 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
SameOrigin- x-content-type-options
nosniff- content-security-policy
default-src 'self' our.umbraco.com *.google.com www.facebook.com marketplace.umbraco.com w3.org *.google-analytics.com www.googletagmanager.com;script-src 'self' 'unsafe-inline' 'unsafe-eval' track.adform.net *.cookietractor.com *.google.com *.google-analytics.com *.googletagmanager.com *.microsoft.com tb.de17a.com s2.adform.net www.facebook.com connect.facebook.net js.monitor.azure.com *.applicationinsights.azure.com www.gstatic.com;style-src 'self' 'unsafe-inline' w3.org;img-src 'self' our.umbraco.com dashboard.umbraco.com w3.org www.facebook.com data: www.googletagmanager.com;frame-src 'self' *.youtube-nocookie.com marketplace.umbraco.com *.youtube.com player.vimeo.com *.microsoft.com www.facebook.com *.googletagmanager.com *.google.com;font-src 'self' data:;connect-src 'self' ws://localhost:* wss://localhost:* http://localhost:* https://localhost:* *.cookietractor.com stats.g.doubleclick.net *.google-analytics.com *.google.com *.googletagmanager.com www.facebook.com wss://*.azureed- strict-transport-security
max-age=31536000