probo.dk
HTML metadata
Technology
- CDN
- Cloudflare
- CMS
- Gatsby
- Fonts
-
- Google Fonts
Third-party hosts loaded (1)
- fonts.googleapis.com×1
DNS records live
- NS
-
- johnathan.ns.cloudflare.com
- ruth.ns.cloudflare.com
- MX
-
- 10 mxa.eu.mailgun.org
- 10 mxb.eu.mailgun.org
- TXT
-
9114deb1d45d43d680bf1b2cb18500bb
- Verified for
-
- GlobalSign
Email authentication strong
- SPF
-
v=spf1 include:eu.mailgun.org ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=reject; pct=100; fo=1; ri=3600; sp=reject; adkim=r; aspf=s; rua=mailto:db890fc5@dmarc.mailgun.org,mailto:5c35028c@inbox.ondmarc.com,mailto:re+c12411a5dd00@inbound.dmarcdigests.com; ruf=mailto:db890fc5@dmarc.mailgun.org,mailto:5c35028c@inbox.ondmarc.com;policy: reject (enforced) · sp=reject - DKIM
- no key found at common selectors
Certificate (current)
WE1
Expires in 54 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-content-type-options
- referrer-policy
- cross-origin-opener-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing frame protection
- missing Permissions Policy
Header values
- referrer-policy
same-origin- x-content-type-options
nosniff- content-security-policy
worker-src 'self' *.probo.dk blob: http://probo.localhost:8000 blob: http://*.probo.localhost:8000 blob:; frame-src 'self' *.probo.dk *.probo.localhost *.probo2.localhost data: *.google.com *.youtube.com *.vimeo.com form.jotform.com form.jotformeu.com www.boligsiden.dk submit.jotformeu.com submit.jotform.com eu-submit.jotform.com a.boligsiden.dk servlet.dmi.dk http://servlet.dmi.dk https://airtable.com/embed/ https://checkout.reepay.com https://iframe.videodelivery.net https://dfanord.wufoo.com/embed/ https://www.google.com/maps/embed/; default-src 'self' 'unsafe-inline' probo.dk *.probo.dk http://probo.localhost:8000 http://*.probo.localhost:8000 https://ekr.zdassets.com https://prosedodk.zendesk.com wss://prosedodk.zendesk.com https://static.zdassets.com app.firmafon.dk upload.videodelivery.net https://dawa.aws.dk probo-test-staticfiles.ams3.cdn.digitaloceanspaces.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' cdn.jsdelivr.net cdnjs.cloudflare.com ajax.googleapis.com www.gstati- strict-transport-security
max-age=31536000; includeSubDomains; preload- cross-origin-opener-policy
same-origin