svtplay.se
HTML metadata
Technology
- CMS
- Next.js
- JS framework
- Next.js
Third-party hosts loaded (1)
- www.svtstatic.se×20
DNS records live
- NS
-
- a1-8.akam.net
- a14-64.akam.net
- a2-65.akam.net
- a3-67.akam.net
- nsa.dnsnode.net
- nsp.dnsnode.net
- nsu.dnsnode.net
- MX
-
- 10 svtplay-se.mail.protection.outlook.com
- TXT
-
Show 4 TXT records
_qbq0huhx4f6be04ab75plb99bbet669d8ddeefbef0f4d25903f22e8681653bdy3n8jv5cfm7tpt5xbwtr83kypbkj7kvvnl1h90mrp8jqgrdhds82lyv39z2wf0x9
- Verified for
-
- Meta
Email authentication weak
- SPF
-
v=spf1 include:spf.protection.outlook.com -allstrict (-all) - DMARC
- not published
- DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCjtYpxjlgH/EExkekeFPXdmmPeXTWWKp0BlPQJpjSMmi9eDobhSt1PNU3bWcgXS02Kt0ZaOKJPfZv0DAwrfX… - selector2:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDrhRwtXRTClcSKN/0D0EIcIHV5vhLDdHWSf89wP8yGpqJ3N3VZqLPpf6cjjxz6jSByl8B1oMIr6vUZVS6x73…
selectors probed - selector1:
Certificate (current)
Amazon RSA 2048 M01
Expires in 292 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- short HSTS max-age
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Permissions Policy
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src blob: data: https://*.imrworldwide.com/ https://*.akamaihd.net https://*.akamaized.net https://*.footprint.net https://*.svt.se https://*.svtplay.se https://analytics.codigo.se https://sb.scorecardresearch.com https://sentry.io https://time.akamai.com https://www.gstatic.com http://www.gstatic.com https://www.svtstatic.se https://firestore.googleapis.com 'self' 'unsafe-eval' 'unsafe-inline' https://svt-direktcenter-avatar.imgix.net https://svt-direktcenter-avatar-stage.imgix.net https://svt-direktcenter.imgix.net https://svt-direktcenter-stage.imgix.net ws://localhost:* http://localhost:* https://accounts.google.com https://appleid.cdn-apple.com https://api.lvis.io http://api.lvis.io https://*.monterosa.cloud http://*.monterosa.cloud wss://*.monterosa.cloud/ ws://*.monterosa.cloud/ https://*.moengage.com https://se-svt-endpoint.2cnt.net;frame-ancestors 'self' https://*.svt.se *.zync.tv- strict-transport-security
max-age=7776000
Links to (1)
- svt.se×1