pool.fi
HTML metadata
Technology
- Server
- nginx
- CMS
- Drupal
- PHP
- 7.4.33 end of life
- jQuery
- 2.1 known XSS (<3.5)
- Analytics
-
- Google Tag Manager
Third-party hosts loaded (3)
- www.googletagmanager.com×2
- js-eu1.hs-scripts.com×1
- www.w3.org×1
Social
Contact
- Phone
DNS records live
- NS
-
- ns3.pool.fi
- ns4.pool.fi
- ns5.pool.fi
- MX
-
- 10 mail.poolpark.fi
- Verified for
-
- Microsoft 365
Email authentication strong
- SPF
-
v=spf1 include:_netblocks.pool.fi include:_netblocks.multitronic.fi ip4:217.77.192.9 ip4:217.77.193.9 -allstrict (-all) - DMARC
-
v=DMARC1; p=quarantine; ruf=mailto:spambot@pool.fi; sp=none; ri=86400policy: quarantine · sp=none - DKIM
-
- default:
v=DKIM1; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCqB5zSR2vSGO4Kz84NdduON4D/KfRA4rQU1/9QZIfCR0dN3WN1M1r+e54OMoLDrReOUBvpFEK7B8wYlgaCLvyOPmQkK…
selectors probed - default:
Certificate (current)
R12
Expires in 42 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- weak frame protection
- missing Permissions Policy
Header values
- referrer-policy
same-origin, same-origin- x-frame-options
SAMEORIGIN, SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src 'none'; script-src 'unsafe-inline' https: 'nonce-eDZhMWMxY2IxNTQxZDQzLjg5MjU0Njcw' 'strict-dynamic'; form-action 'self'; frame-ancestors 'none'; style-src * 'unsafe-inline'; object-src 'none'; base-uri 'none'; img-src *; font-src *; connect-src 'self'- strict-transport-security
max-age=63072000; includeSubDomains;, max-age=63072000; includeSubDomains
Links to (9)
- pedersore.fi×1
- pav.fi×1
- narpesgronsaker.fi×1
- narpes.fi×1
- narko.com×1
- linkedin.com×1
- instagram.com×1
- google.fi×1
- facebook.com×1
Linked from (1)
- timle.fi×1