soderbergpartners.se
HTML metadata
Technology
- CDN
- Cloudflare
- CMS
- Gatsby
Third-party hosts loaded (2)
- cxppusa1formui01cdnsa01-endpoint.azureedge.net×1
- dev.visualwebsiteoptimizer.com×1
Social
DNS records
Email authentication strong
- SPF
-
v=spf1 include:spf.protection.outlook.com include:eur.pb-dynmktge.com include:spf.mailjet.com include:_spf-a.soderbergpartners.se include:_spf-b.soderbergpartners.se include:trustpilotservice.com -allstrict (-all) - DMARC
-
v=DMARC1; p=reject; rua=mailto:dmarc_agg@vali.email; ruf=mailto:ruf_dmarc@soderbergpartners.se; fo=1policy: reject (enforced) - DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAyZYyJgGc5CYn8h24ErSYpvft7kFYIxOfRNjx3ek7ArDotJuTnVJq9SlBny5FZRF/PDgGxbLj/Zna6P…
selectors probed - selector1:
Certificates
Loading certificate
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN- permissions-policy
microphone=()- x-content-type-options
nosniff- content-security-policy
default-src 'self'; connect-src 'self' 'unsafe-inline' https: wss:; font-src 'self' 'unsafe-inline' https: data:; style-src 'self' 'unsafe-inline' https:; script-src 'self' 'unsafe-inline' https://*.cookiebot.com https://www.googletagmanager.com https://widget.trustpilot.com https://www.buzzsprout.com https://maps.googleapis.com https://www.google-analytics.com https://www.facebook.com https://*.clarity.ms https://api.linkedin.com https://connect.facebook.net https://cxppusa1formui01cdnsa01-endpoint.azureedge.net https://addrevenue.io https://measurement.soderbergpartners.se https://js.hs-scripts.com https://*.readpeak.com 'unsafe-eval' https://bat.bing.com https://rns.matelso.de https://cdn.adt361.com https://js-eu1.hs-scripts.com https://js-eu1.hubspot.com https://js-eu1.hs-analytics.net https://js-eu1.hsadspixel.net https://js-eu1.hs-banner.com https://dev.visualwebsiteoptimizer.com https://googleads.g.doubleclick.net https://static.hsappstatic.net https://www.youtube.com https://ap- strict-transport-security
max-age=30758400