t-d.se
HTML metadata
Technology
Third-party hosts loaded (3)
- piwik-ext.vgregion.se×2
- cdn.jsdelivr.net×1
- td.azure-api.net×1
DNS records live
- NS
-
- ns1.vgregion.se
- ns2.vgregion.se
- ns4.vgregion.se
- ns5.vgregion.net
- TXT
-
_globalsign-domain-verification=7J89ivnavAswFbFlBAf9hqzTQj0X0jz8PSUJlGg9eNgoogle-site-verification=2r7NFZnqz1EltljvPQD4ZxQqFzMK8laBn3Meexz0hY8
Email authentication no MX
- SPF
- not published
- DMARC
- not published
- DKIM
- no key found at common selectors
Certificate (current) wrong cert
GlobalSign RSA OV SSL CA 2018
Expires in 200 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-content-type-options
- referrer-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing frame protection
- missing Permissions Policy
Header values
- referrer-policy
same-origin- x-content-type-options
nosniff- content-security-policy
default-src 'self'; script-src 'unsafe-inline' 'unsafe-eval' 'self' https://privacy-proxy.usercentrics.eu/ https://web.cmp.usercentrics.eu/ https://*.vgrblogg.se/ https://*.boost.ai/ https://*.entryscape.com https://*.stratsys.com/ https://piwik-ext.vgregion.se/ https://piwik-ext.vgregion.se/piwik.js https://*.vgregion.se https://*.vimeocdn.com https://player.vimeo.com/ https://www.youtube.com https://cdn.siteimprove.net/ https://vgrintern.boost.ai https://vgregion.esmaker.net/ https://ssl.webserviceaward.com/; style-src 'unsafe-inline' 'self' https://*.vgrblogg.se/ https://*.vimeocdn.com https://ssl.webserviceaward.com/wsc/client/wscSelVisit.css https://*.stratsys.com/ https://*.vgregion.se https://cdn.jsdelivr.net/npm/vuetify@2.x/dist/vuetify.min.css; object-src 'none'; base-uri 'self'; connect-src 'self' https://privacy-proxy.usercentrics.eu/ https://consent-api.service.consent.usercentrics.eu/ https://v1.api.service.cmp.usercentrics.eu/ https://*.vgrblogg.se/ https://*.boost.ai/ ht- strict-transport-security
max-age=31536000