nuug.no

.no dns crawl

First seen 2026-05-11 · Last seen 2026-05-17 · ok HTTP/1.1 200 1582 ms crawled 2026-05-17

NO · 158.36.191.213 · AS224 Kunnskapssektorens Tjenesteleverandor

Reputation 92/100 no dmarc policy

Classifying

HTML metadata

Title
Norwegian UNIX User Group

Technology

Server
Apache

Contact

Email

Registration

Registrar
Domeneshop AS
Created
1999-11-14
Updated
2026-02-12
Name servers
  • ns1.nuug.no
  • ns.hyp.net

DNS records

Email authentication weak

SPF
v=spf1 a mx ip4:185.181.61.63 ip4:158.36.191.128/25 ip6:2a03:94e0:182c::1 include:spf.uio.no -all
strict (-all)
DMARC
not published
DKIM
no key found at common selectors

Certificate (current)

R13
from 2026-04-12 to 2026-07-11
Expires in 54 days

HTTP security headers

Header hygiene 80/100 Checked live page: https://nuug.no/

present
  • strict-transport-security
  • content-security-policy
  • x-frame-options
  • x-content-type-options
  • referrer-policy
findings
  • short HSTS max-age
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
  • missing Permissions Policy
Header values
referrer-policy
same-origin
x-frame-options
SAMEORIGIN
x-content-type-options
nosniff
content-security-policy
default-src 'self' 'unsafe-inline' 'unsafe-eval' data: *.youtube.com *.openstreetmap.org *.vimeo.com *.frikanalen.no *.nuug.no yewtu.be *.kjemi.uio.no *.oreilly.com *.skolelinux.de *.googleapis.com remarkjs.com *.gstatic.com api.flattr.com; img-src 'self' twitter-badges.s3.amazonaws.com nuug.no data: secure.gravatar.com blob:; script-src-elem 'self' 'unsafe-inline' yewtu.be remarkjs.com *.flattr.com digg.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' yewtu.be blob: *.googleapis.com *.gstatic.com; style-src 'self' 'unsafe-inline' *.googleapis.com; connect-src 'self' *.nuug.no *.googleapis.com; worker-src 'self' blob:; frame-src 'self' *.youtube.com blob:; frame-ancestors 'self' nuug.no; report-uri /csp-report-endpoint;
strict-transport-security
max-age=10886400; includeSubDomains; preload

Links to (5)