svd.se
HTML metadata
Technology
- CDN
- Amazon CloudFront
- Server
- nginx
- CMS
- Gatsby
Third-party hosts loaded (5)
- akamai.vgc.no×13
- esm.schibsted.tech×4
- adsdk.microsoft.com×1
- cogwheel.inventory.schibsted.io×1
- mediacdn.prenly.com×1
Social
Contact
- Phone
- Address
- Kungsbron 13, 10517, Stockholm
DNS records live
- NS
-
- dns5.telia.com
- dns6.telia.com
- ns1.schibsted.se
- ns2.as33976.net
- MX
-
- 1 aspmx.l.google.com
- 10 alt3.aspmx.l.google.com
- 10 alt4.aspmx.l.google.com
- 5 alt1.aspmx.l.google.com
- 5 alt2.aspmx.l.google.com
- TXT
-
Show 8 TXT records
_varnish-cdn-verify=4ypk38W5jL1B18oHv2evCPfacebook-domain-verification=zbjo5txwew1rvguz0akcalz9ey78fr_varnish-cdn-verify=fcOPzVU0onWrjJPdAmZjXZapple-domain-verification=eohC5QhZOA1R8Cvqgoogle-site-verification=KDmAWOIQ9zDOlTHIh9xdBx0IcLoTYt02_SlpJZBvns4google-site-verification=_o3JiDvN_sVd3ZN8ZDyr8TrkK62Fio3OKUTpLGpiCd8fastly-domain-delegation-swsfFC5CRfjn43Xk-596685-2023-04-171password-site-verification=ZV2VQDENMZCQLMY2K3UP3NJDMU
Email authentication strong
- SPF
-
v=spf1 a:smtp.schibsted.se a:psmtp.schibsted.se include:_u.svd.se._spf.smart.ondmarc.com -allstrict (-all) - DMARC
-
v=DMARC1;p=reject;rua=mailto:af0d07b7@inbox.ondmarc.com;rf=afrf;ruf=mailto:af0d07b7@inbox.ondmarc.com;pct=100policy: reject (enforced) - DKIM
-
Show 4 DKIM selectors
- google:
v=DKIM1;k=rsa;p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDMbOuTWu87CSCROpgN/Ajw5zig6/zRMes2mtiuvY+1bdBpVmO6PrqUnu/P0TnhNqR+hY/C1EtrRT6ll8xLSIde… - k1:
k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDbNrX2cY/GUKIFx2G/1I00ftdAj713WP9AQ1xir85i89sA2guU0ta4UX1Xzm06XIU6iBP41VwmPwBGRNofhBVR+e6WHUo… - s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA3VJZwmvffpDi9chJ1OLHjDrsgwULqJz6b3HYNP283xE8qJUoyp2nQnRVKnenMoIZ+tjNC81GVaE0yufgjx… - s2:
k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDFSuj692J+5SG9Wq3o2oeYyPfY0fadLAH/rELjOgXyfhUts5rxDlnat/uV8Z9kS9PNxb6Cj6Y3+Y+nJZogoyKYfV…
selectors probed - google:
Certificate (current)
Amazon RSA 2048 M04
Expires in 149 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
DENY- permissions-policy
accelerometer=(), camera=(), cross-origin-isolated=(), display-capture=(), geolocation=(self), gyroscope=(), keyboard-map=(), magnetometer=(), microphone=(), payment=(), publickey-credentials-get=(), usb=(), xr-spatial-tracking=(), clipboard-read=(self), clipboard-write=(self), hid=(), fullscreen=(self "https://www.youtube.com" "https://www.youtube-nocookie.com"), idle-detection=(), unload=()- x-content-type-options
nosniff- content-security-policy
frame-ancestors 'self' *.svd.se; default-src https: data: blob: wss: react-js-navigation: android-webview: android-webview-video-poster: 'unsafe-inline' 'unsafe-eval' *.schibsted.com *.schibsted.io secure.adnxs.com; report-uri https://svd.report-uri.com/r/d/csp/enforce; img-src https: blob: data: secure.adnxs.com *.schibsted.com- strict-transport-security
max-age=31536000; includeSubDomains