orebro.se
HTML metadata
Technology
- Stack
- Java
Third-party hosts loaded (1)
- static.rekai.se×1
Social
Contact
- Phone
DNS records live
- NS
-
- ns1.orebro.se
- ns2.orebro.se
- MX
-
- 10 orebro-se.mail.protection.outlook.com
- TXT
-
Gut+uDkgNmmhnhYuwc1ObccQZzUvDkAI/CF9ZqDtsTOaVz7N4+qqW3UUURr8T29wx5ByJ0kUAAw54CPfq5G9EQ==lfhf29m3jgprscg697pk3zpxzntsdmgn
- Verified for
-
- Apple
- Microsoft 365
Email authentication partial
- SPF
-
v=spf1 ptr ip4:194.103.205.171 ip4:194.103.205.83 ip4:217.78.31.206 a:mail4.axbyte.com a:smtp.openlib.se a:relay2.hostnet.se a:mail.sitevision-cloud.net a:smtp01.emea.sabacloud.com include:spf.protection.outlook.com include:all._spf.plma.se -allstrict (-all) - DMARC
-
v=DMARC1;p=none;pct=100;rua=mailto:dmarc-rua@orebro.se;ruf=mailto:dmarc-ruf@orebro.se;fo=1policy: none (monitoring only) - DKIM
-
- k2:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAv2aC2KjGKLOwTweBY5A9RpjsxaBXR9r7OAU6U8/zn92ivImI75naUujWbItRI/QmL1jy5PWGqLwoUA…
selectors probed - k2:
Certificate (current)
R12
Expires in 64 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Permissions Policy
Header values
- referrer-policy
no-referrer- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
script-src 'self' 'unsafe-eval' 'unsafe-inline' map.naturkartan.se/embed.js karta.orebro.se *.imbox.io svanalytics.containers.piwik.pro view.rekai.se static.rekai.se *.readspeaker.com storage.ebbot.eu storage.gra.cloud.ovh.net ebbot-experimental.storage.googleapis.com code.jquery.com oppnadata.skl.se oppnadata.skr.se *.mediaflow.com mfstatic.com code.highcharts.com; connect-src 'self' api.friendlycaptcha.com eu-api.friendlycaptcha.eu *.imbox.io view.rekai.se api.kolada.se *.mediaflow.com mfstatic.com karta.orebro.se *.piwik.pro *.readspeaker.com storage.gra.cloud.ovh.net oppnadata.skl.se oppnadata.skr.se wss://ebbot.eu https://ebbot.eu api.paloma.se; frame-src 'self' *.orebro.se *.imbox.io futureweb.orebro.se map.naturkartan.se; frame-ancestors 'self'; form-action 'self' futureweb.orebro.se; base-uri 'self'; object-src 'none'; child-src blob:;- strict-transport-security
max-age=31536000; includeSubDomains; preload