prizz.fi
HTML metadata
Technology
- jQuery
- 3.3.1 known XSS (<3.5)
- Analytics
-
- Google Tag Manager
- Cookie consent
-
- Cookiebot
- Fonts
-
- Adobe Fonts
- Google Fonts
Third-party hosts loaded (11)
- cdnjs.cloudflare.com×4
- www.googletagmanager.com×3
- code.jquery.com×2
- cdn.jsdelivr.net×1
- consent.cookiebot.com×1
- fonts.googleapis.com×1
- px.ads.linkedin.com×1
- stackpath.bootstrapcdn.com×1
- use.typekit.net×1
- www.facebook.com×1
- www.google.com×1
Social
Contact
- Phone
Registration
- Created
- 1990-12-31
- Name servers
-
- ns13.ictpori.fi [185.87.111.83] [ok]
- ns11.ictpori.fi [185.118.225.11] [ok]
- ns12.ictpori.fi [185.118.225.12] [ok]
- ns14.ictpori.fi [185.87.111.192] [ok]
DNS records live
- NS
-
- ns11.ictpori.fi
- ns12.ictpori.fi
- ns13.ictpori.fi
- ns14.ictpori.fi
- MX
-
- 10 prizz-fi.mail.protection.outlook.com
- TXT
-
PjBN0zYlcO+hYm+KPmBm8HasOK4C9qlWPZoF9NmloDF7L08+a1A9IGmEP85zXF1NEAxoXTWM+F903RsBuyMUvQ==
- Verified for
-
- Microsoft 365
Email authentication strong
- SPF
-
v=spf1 mx a ip4:194.89.239.100 ip4:194.89.239.101 ip4:194.89.239.102 ip4:194.89.239.103 ip4:213.214.170.95 a:smtp.dna044.com ip4:185.18.79.120 ip4:185.118.226.30 include:spf.mailjet.com include:_spf.emaileri.fi include:spf.protection.outlook.com include:spf.lianamailer.com include:sendgrid.net -allstrict (-all) - DMARC
-
v=DMARC1; p=reject; pct=100; aspf=s;policy: reject (enforced) - DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCkCQZv5/K8NBI32RQjS5smBkiGDubXtfTtkFXLVB+RhGi3q5+ceOMADT3G2M4BN15EU1E4wUIRl7L9mWqFf/… - s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAudki7QyV1z/tTrdDt+YQJlCp2o0shtrWidr4rzU52MHv8/ndXTuDGOWkyc32/LMecuJ+1H6EyLYM4pJmfi… - s2:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA0WwyO9w326e230V0julxj7QTFVtB8zpf1f1WAzM6yW88VoafzWbci2IJSMyX5oc1/g/yLZQ0BWwr5IdzjY…
selectors probed - selector1:
Certificate (current)
R12
Expires in 41 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing frame protection
- missing content type protection
- missing Referrer Policy
- missing Permissions Policy
Header values
- content-security-policy
default-src * 'unsafe-inline' 'unsafe-eval' data: blob:;- strict-transport-security
max-age=63072000; includeSubDomains; preload