portfolio.no
HTML metadata
Technology
- Server
- nginx
- jQuery
- 2.1.3 known XSS (<3.5)
DNS records live
- NS
-
- ns01.no.brand.one.com
- ns02.no.brand.one.com
- Verified for
-
- Microsoft 365
Email authentication no MX
- SPF
-
v=spf1 redirect=_spf.portfolio.nomissing all - DMARC
-
v=DMARC1;p=quarantine;rua=mailto:049590ef2e@rua.easydmarc.eu;ruf=mailto:049590ef2e@ruf.easydmarc.eu;fo=1;policy: quarantine - DKIM
-
- s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA31K0tlRcG9SNWx1Eo14waez7Fkr8OaNPKDDE1AdTACtrFgrkg1VMtvlOHlMNqJHvhhsAkUIYTPumFe7Gye… - s2:
k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCpwABgyzjDV/pWUN5hIlFzxUWg54SjAaEB1+gFRLTRlPGnD2nkE1BShjceGxClpNdaWla1oZmLOpW6jDJWOJbksV…
selectors probed - s1:
Certificate (current)
E7
Expires in 40 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy-report-only
- x-content-type-options
- referrer-policy
- findings
-
- missing Content Security Policy
- missing frame protection
- missing Permissions Policy
Header values
- referrer-policy
origin-when-cross-origin- x-content-type-options
nosniff- strict-transport-security
max-age=31536000- content-security-policy-report-only
default-src https: data: 'unsafe-inline' 'unsafe-eval'; connect-src 'self' https: wss:; report-uri https://csp.prod.devops.forlagshuset.no/csp/report-only; report-to csp-endpoint
Links to (3)
- w3.org×1
- fagbokforlaget.no×1
- brreg.no×1