rayo.no

.no crawl

First seen 2026-05-28 · Last seen 2026-05-28 · ok HTTP/1.1 200 884 ms crawled 2026-05-31

IE · 52.212.243.181 · AS16509 Amazon.com, Inc.

Reputation 92/100 no dmarc policy

Classifying

HTML metadata

Title
Rayo - Den beste musikken til enhver stemning.
Description
Lytt til Norges beste radiokanaler og podcast helt gratis på Rayo. Verdens beste musikk. Døgnet rundt.
Language
no
Canonical
https://rayo.no/

Open Graph

url
https://rayo.no/
local
no_NO
title
Rayo - Den beste musikken til enhver stemning.
site name
Rayo
description
Lytt til Norges beste radiokanaler og podcast helt gratis på Rayo. Verdens beste musikk. Døgnet rundt.

Technology

Server
nginx
CMS
Next.js
JS framework
Next.js
Analytics
  • Google Tag Manager

Third-party hosts loaded (2)

  • media.bauerradio.com×13
  • www.googletagmanager.com×1

DNS records live

NS
  • ns-1064.awsdns-05.org
  • ns-1967.awsdns-53.co.uk
  • ns-23.awsdns-02.com
  • ns-925.awsdns-51.net
MX
  • 0 rayo-no.mail.protection.outlook.com
Verified for
  • Google
  • Microsoft 365

Email authentication weak

SPF
v=spf1 include:mail.zendesk.com include:spf.protection.outlook.com -all
strict (-all)
DMARC
not published
DKIM
  • selector1: v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAxl4sS68glMwD1XcRoRtS5+qrI9yDIZmEgj4TpcnK3/nnwQkCHlO/7biAJCBaUkvYm197thLCn5qtLP…
selectors probed

Certificate (current)

Amazon RSA 2048 M04
from 2025-08-22 to 2026-09-21
Expires in 112 days

HTTP security headers

Header hygiene 80/100 Checked live page: https://rayo.no/

present
  • strict-transport-security
  • content-security-policy
  • x-frame-options
  • x-content-type-options
findings
  • short HSTS max-age
  • CSP allows unsafe inline scripts/styles
  • missing Referrer Policy
  • missing Permissions Policy
Header values
x-frame-options
SAMEORIGIN
x-content-type-options
nosniff
content-security-policy
default-src https:;script-src https: data: 'unsafe-inline' 'unsafe-eval';style-src https: 'unsafe-inline';img-src https: data: blob:;media-src https: data: blob:;font-src https: data:;connect-src https: wss:;worker-src 'self' blob:;upgrade-insecure-requests;
strict-transport-security
max-age=600

Links to (5)