resursbank.se
HTML metadata
Technology
- CMS
- WordPress
- Analytics
-
- Google Tag Manager
- Cookie consent
-
- OneTrust
Third-party hosts loaded (4)
- cdn.cookielaw.org×2
- resursbank-prd-images.s3.eu-west-1.amazonaws.com×2
- static.zdassets.com×1
- www.googletagmanager.com×1
Social
Contact
- Phone
DNS records live
- NS
-
- ns-1232.awsdns-26.org
- ns-1700.awsdns-20.co.uk
- ns-359.awsdns-44.com
- ns-664.awsdns-19.net
- MX
-
- 10 resursbank-se.mail.protection.outlook.com
- TXT
-
rovag_verification_token=50B1F79028C1418BA4D46A380D5137C7_c2gc08n0ddbdi6ahl00kco2na1s9loj
- Verified for
-
- Dropbox
- Microsoft 365
- Yahoo
Email authentication strong
- SPF
-
v=spf1 redirect=_spf.resurs.semissing all - DMARC
-
v=DMARC1; p=quarantine; pct=100; rua=mailto:dmarc-rua@resursbank.se; ruf=mailto:dmarc-ruf@resursbank.se; fo=1policy: quarantine - DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEArYXpNgFP+CidNCVHIJHv/ABAHd1fA+uXYG6ZZO0NAhBo+1mMMoln1bp1iVxoBz7zeaHgJ15VFrMekA…
selectors probed - selector1:
Certificate (current)
Amazon RSA 2048 M04
Expires in 151 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- cross-origin-opener-policy
- cross-origin-resource-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Permissions Policy
Header values
- referrer-policy
no-referrer- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src 'self' *.amazonaws.com;media-src 'self' *.amazonaws.com data: *.ace.teliacompany.com *.zdassets.com;script-src * 'unsafe-inline' 'unsafe-eval';img-src * data:;style-src 'self' 'unsafe-inline' *.teliacompany.com *.google.com *.humany.net *.googleapis.com *.gstatic.com *.amazonaws.com;connect-src 'self' *.google-analytics.com *.googleadservices.com *.linkedin.com *.zendesk.com wss://*.zendesk.com *.zdassets.com *.googletagmanager.com *.amazonaws.com *.humany.net *.google.com *.google.se *.resursbank.se *.resursbank.no *.resursbank.dk *.resursbank.fi *.resurs.com *.integration.resurs.com *.doubleclick.net *.googleapis.com *.amplitude.com *.teliacompany.net *.resurs.loc *.ellos.resursbank.24hr.se wss://*.resurs.se wss://*.resurs.fi wss://*.resurs.dk wss://*.resurs.no *.hotjar.io *.hotjar.com wss://*.hotjar.com wss://*.hotjar.io widget.datablocks.se *.taboola.com *.bing.com *.bing.net *.mfn.se *.googlesyndication.com cdn.cookielaw.org *.onetrust.com *.elastic-cloud.com *.resurs.- strict-transport-security
max-age=31536000; includeSubDomains; preload- cross-origin-opener-policy
unsafe-none- cross-origin-resource-policy
cross-origin
Links to (8)
- resurs.com×1
- linkedin.com×1
- konsumentverket.se×1
- instagram.com×1
- google.com×1
- fi.se×1
- facebook.com×1
- apple.com×1