strawberry.dk
HTML metadata
Technology
- Analytics
-
- Google Tag Manager
Third-party hosts loaded (10)
- images.ctfassets.net×24
- cdn-eu.dynamicyield.com×2
- design-system.webprod.eberry.digital×2
- rcom-eu.dynamicyield.com×2
- st-eu.dynamicyield.com×2
- www.googletagmanager.com×1
- www.strawberry.fi×1
- www.strawberry.no×1
- www.strawberry.se×1
- www.strawberryhotels.com×1
Social
DNS records live
- NS
-
- ns-cloud-e1.googledomains.com
- ns-cloud-e2.googledomains.com
- ns-cloud-e3.googledomains.com
- ns-cloud-e4.googledomains.com
- MX
-
- 1 aspmx.l.google.com
- 10 alt3.aspmx.l.google.com
- 10 alt4.aspmx.l.google.com
- 5 alt1.aspmx.l.google.com
- 5 alt2.aspmx.l.google.com
- TXT
-
Show 6 TXT records
68dcb1166bfbb4c3a287ac519a287a934d93a396512bd58fb4466a0e03f95b11b29354d9524b27bed4ec49665cd71dcb7fd742e3db040a81946a6269b71947ce_b5vov6n811fz619d9piir0bbj4hz9ikdetectify-verification=9e555d6ecfb1a08bd5650ea2b600c628329b195846c93c8794c2e862af33886ff6dafb70bf9834a7969420719bfa8ac3proxy-ssl.webflow.com
- Verified for
-
- Atlassian
- Microsoft 365
- Slack
- Stripe
Email authentication strong
- SPF
-
v=spf1 include:_u.strawberry.dk._spf.smart.ondmarc.com ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=reject; pct=100; sp=reject; rua=mailto:71d20dc5@inbox.ondmarc.com; ruf=mailto:71d20dc5@inbox.ondmarc.com; adkim=r; aspf=r; fo=1; rf=afrf; ri=3600policy: reject (enforced) · sp=reject - DKIM
-
- google:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAsO8vaxdVwI7aU0pW/4zQqGQFL40fiiqWK/tuHBkWfvvFGkExEdHRhQzqKbO6oGn0SuQ0AM3UZVUmp+… - s1:
k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQC57C3QYDmppjF7lWx0ce4CLmR/M0YlnIDKP3Jpymen0BKchtuHLoYV+uYGS50ujqRStYDkrClBjK7m7J02e3aQnV9Jppd…
selectors probed - google:
Certificate (current)
Buypass Class 3 CA 2
Expires in 75 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- cross-origin-opener-policy
- cross-origin-resource-policy
- findings
-
- CSP allows unsafe inline scripts/styles
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN- permissions-policy
accelerometer=(), camera=(), geolocation=(), gyroscope=(), magnetometer=(), microphone=(), usb=()- x-content-type-options
nosniff- content-security-policy
script-src 'nonce-8e85eb1b05c9a0f4' 'strict-dynamic' 'unsafe-inline' 'unsafe-eval' http: https:; base-uri 'none'; frame-ancestors https://app.contentful.com; require-trusted-types-for 'script'- strict-transport-security
max-age=31536000; includeSubDomains; preload- cross-origin-opener-policy
same-origin- cross-origin-resource-policy
cross-origin