runa.dk
HTML metadata
Technology
- CMS
- Next.js
- JS framework
- Next.js
Social
Contact
- Phone
DNS records live
- NS
-
- ns.scannet2.dk
- ns2.scannet2.dk
- MX
-
- 10 runa-dk.mail.protection.outlook.com
Email authentication strong
- SPF
-
v=spf1 include:spf.protection.outlook.com -allstrict (-all) - DMARC
-
v=DMARC1; p=reject; rua=mailto:60bdf0bd5f571@dmarc.centerasecurity.com;policy: reject (enforced) - DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCX6VvQ/KyPfPeQNaGo5i6hBMrPihUga/PdCizoYoo5SMX65xEqbVP6gqvJ1D4HHO/CTpZM1rvon3iu6mQMhD… - selector2:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCb2JyQu8x/qnsl6zFZFBI9OQigYVgw40yxfHtLia0fqefcyU36FlYKfLUwTOgUAKyln0QugJ0csd55HM3Krj…
selectors probed - selector1:
Certificate (current)
Thawte TLS RSA CA G1
Expires in 120 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Permissions Policy
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src 'self' data: 'unsafe-inline' 'unsafe-eval' https://*.cookieinformation.com https://*.piwik.pro https://*.lb.dk https://*.bauta.dk https://*.runa.dk https://*.lbforsikring.dk https://*.lbforeningen.dk https://*.lberhverv.dk https://*.teliacompany.com https://*.teliacompany.net https://lbf.humany.net https://*.trustpilot.net https://*.trustpilot.com https://*.telemetric.dk https://*.doubleclick.net https://*.facebook.net https://*.facebook.com https://*.google.com https://*.google.dk https://*.bing.com https://*.googletagmanager.com https://*.site.com https://*.salesforce-scrt.com https://*.queue-it.net https://*.queue-it.com https://dawa.aws.dk https://*.dawa.aws.dk https://*.bing.net https://bing.net https://www.scalepoint.com https://*.scalepoint.com https://*.googleadservices.com https://*.licdn.com https://*.linkedin.com script-src 'self' data: 'unsafe-inline' 'unsafe-eval' https://*.cookieinformation.com https://*.piwik.pro https://*.lb.dk https://*.bauta.dk https://*.r- strict-transport-security
max-age=31536000; includeSubDomains; preload, max-age=63072000
Links to (6)
- linkedin.com×1
- lbforsikring.dk×1
- lberhverv.dk×1
- lb.dk×1
- facebook.com×1
- bauta.dk×1