storebrand.se
HTML metadata
Technology
- Server
- nginx
- Cookie consent
-
- OneTrust
Third-party hosts loaded (1)
- cdn.cookielaw.org×1
Social
Contact
- Phone
DNS records live
- NS
-
- ns1-07.azure-dns.com
- ns2-07.azure-dns.net
- ns3-07.azure-dns.org
- ns4-07.azure-dns.info
- MX
-
- 10 mxa-0028d802.gslb.pphosted.com
- 10 mxb-0028d802.gslb.pphosted.com
- TXT
-
Tpkt6yEqJjww5ePovOHb1AfrMdphdC4doqOCHNR0wAMmfJpoSwoqJDV99c7p2EQSRXm5KrkgcrVfjXeeD2WTBA==
- Verified for
-
- Atlassian
- DocuSign
- GlobalSign
- Microsoft 365
Email authentication strong
- SPF
-
v=spf1 include:_spf.storebrand.com include:servers.mcsv.net ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=reject; fo=1; rua=mailto:dmarc_rua@emaildefense.proofpoint.com; ruf=mailto:dmarc_ruf@emaildefense.proofpoint.compolicy: reject (enforced) - DKIM
-
- google:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAkAlbra/iCtLF++BXjGf0KWwV+2fQvpjbF3tlesQOJGVdnB/BtVtJSe/8RCuwVnwKZgOg2ngjTidemr… - s1:
v=DKIM1; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAqKyLjeDwAle59I1/MtubUrUHx38xPdafA6lIqnAWmGR1Th0ADHr4DUOiQWbkwKFugYkr7PWk52QYBgC05PRTT…
selectors probed - google:
Certificate (current)
GlobalSign RSA OV SSL CA 2018
Expires in 287 days
HTTP security headers
- present
-
- content-security-policy
- findings
-
- missing HSTS
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing frame protection
- missing content type protection
- missing Referrer Policy
- missing Permissions Policy
Header values
- content-security-policy
default-src 'self';form-action 'self';media-src 'self';worker-src 'self' blob:;script-src 'self' 'unsafe-inline' 'unsafe-eval' https://spp.my.site.com https://spp--uat.sandbox.my.site.com https://spp.my.salesforce.com https://spp.lightning.force.com https://static.lightning.force.com https://b.static.lightning.force.com https://bat.bing.com https://bat.bing.net https://blocks.insurely.com/ https://cdn.cookielaw.org/ https://observe.spp.se/ https://observe.storebrandfonder.se/ https://observe.storebrand.se/ https://*.googletagmanager.com https://www.google-analytics.com/ https://*.googleadservices.com https://*.google.com https://*.googlesyndication.com https://*.doubleclick.net https://*.hotjar.com/ https://*.hotjar.io/ https://snap.licdn.com https://px.ads.linkedin.com https://px4.ads.linkedin.com https://p.adsymptotic.com https://cdn.linkedin.oribi.io https://gw.linkedin.oribi.io https://dc.ads.linkedin.com https://sjs.bizographics.com https://www.youtube.com/ https://cdn.screen9.com