prevent.se
HTML metadata
Technology
- Server
- Microsoft-IIS
- Stack
- ASP.NET
- Analytics
-
- Google Analytics
- Google Tag Manager
Third-party hosts loaded (2)
- www.google-analytics.com×1
- www.googletagmanager.com×1
Social
Contact
DNS records live
- NS
-
- ns1.loopia.se
- ns2.loopia.se
- MX
-
- 1 prevent-se.mail.protection.outlook.com
- TXT
-
Show 5 TXT records
2d7t8t0gbkgci35d4iqke1gui9rc0m8ddu9fqpjjc54g8p85t29remarkable-domain-verification=ba1e2a0b-4a75-447c-8ce5-14f24453e84ahOl1mZb7w1Ie/Y0G6jvOt3sm1Ed3hZYgA2Yf93MJtyhsPc+oB+e3m8L9fb51JFEGTKSlwf3A1F7fsYcOiUELnA==dju44jtauen530085vmhitnte0
- Verified for
-
- GlobalSign
Email authentication strong
- SPF
-
v=spf1 include:spf.mailjet.com mx a ip4:31.208.18.142 ip4:31.208.18.143 ip4:31.208.18.146 ip4:31.208.18.147 include:mailanyone.net include:_spf.anpasia.com include:_spf.anpdm.com include:spf.protection.outlook.com include:spf.ilnet.se ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=quarantine; pct=100policy: quarantine - DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCMSJHpI6EHHHq7HyUiPyMYn1Q/RkKSBROOPUchFAtRUn7hrDIKYeQYozvLxKiNHLeytNcRL8py13WXTkHqtt…
selectors probed - selector1:
Certificate (current)
GlobalSign RSA OV SSL CA 2018
Expires in 195 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
sameorigin- x-content-type-options
nosniff- content-security-policy
default-src 'self';img-src 'self' data: *.bing.com *.adtrafficquality.google *.doubleclick.net *.bing.net www.google.com delivery.consentmanager.net pagead2.googlesyndication.com tpc.googlesyndication.com px.ads.linkedin.com www.googletagmanager.com www.facebook.com www.linkedin.com px.ads.linkedin.com i.ytimg.com www.google-analytics.com cdn.consentmanager.net *.delivery.consentmanager.net dl.episerver.net; font-src 'self' script.hotjar.com dl.episerver.net fonts.gstatic.com;style-src 'self' 'unsafe-inline' dl.episerver.net fonts.googleapis.com cdn.jsdelivr.net;script-src 'self' 'unsafe-inline' *.bing.net *.adtrafficquality.google *.bing.com *.publit.com pagead2.googlesyndication.com tpc.googlesyndication.com securepubads.g.doubleclick.net www.youtube.com snap.licdn.com connect.facebook.net static.ws.apsis.one script.hotjar.com static.hotjar.com *.delivery.consentmanager.net delivery.consentmanager.net cdn.consentmanager.net 'unsafe-eval' www.googletagmanager.com www.google-analytics.- strict-transport-security
max-age=31536000
Links to (7)
- facebook.com×1
- instagram.com×1
- libsyn.com×1
- linkedin.com×1
- office.com×1
- tt.se×1
- youtube.com×1