tokmanni.fi
HTML metadata
Technology
- CMS
- Gatsby
- Analytics
-
- Google Tag Manager
Third-party hosts loaded (8)
- d2oarllo6tn86.cloudfront.net×2
- js.klevu.com×2
- adtr.io×1
- js.live.kustom.co×1
- res.cloudinary.com×1
- s3.eu-central-1.amazonaws.com×1
- statsjs.klevu.com×1
- www.googletagmanager.com×1
Social
DNS records live
- NS
-
- ns1-37.azure-dns.com
- ns2-37.azure-dns.net
- ns3-37.azure-dns.org
- ns4-37.azure-dns.info
- MX
-
- 10 spamshield.seclan.com
- TXT
-
hj-ownership=7WAXXNyYiGZ1kGEb1naMijAuEwKqwsOfyw0aYBmI12n80ObRCQWFhYao0qlKvOLWpsy/WTbn2olJUjNhm95PHH4L8v9Msp2tDhnEg==
- Verified for
-
- Meta
- Microsoft 365
Email authentication partial
- SPF
-
v=spf1 mx ip4:192.89.29.0/25 ip4:192.89.123.25/32 ip4:185.43.88.190 ip4:109.68.134.51 ip4:194.89.249.196 ip4:109.68.134.52 ip4:185.244.246.0/23 ip4:213.255.179.248/29 a:smtp.logium.com a:stdsaasmail.basware-saas.com ip4:62.71.2.202 ip4:213.255.179.252 ip4:23.253.32.145 include:network.mynewsdesk.com include:spf.protection.outlook.com ~allsoftfail (~all) - DMARC
-
v=DMARC1;p=none;rua=mailto:dmarc-report@tokmanni.fi;policy: none (monitoring only) - DKIM
-
Show 5 DKIM selectors
- selector1:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQC2oytfGj1AtxRcFHuiFy7UQ1M3UScQ0VX+wlNnQDa+tsfYtKdoG3XrIIAI49+hOxhgEDS8wLOXigLqietcoI… - selector2:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAsuva0RDWtNu7T9E6UFoGvAGjndIEXcSYSj6qIRP8TJqNn6RWNAh55IMSgDP14RxGgFCZ/bvB9kowsl… - s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA6C5qcj0pIHxtshwJm+hQejAzqcOxRMIAdFARBxpQKvW+38+8oM7TFV66mjUL6a6X1cRe5n50bR838N1eKp… - s2:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA5qomoftScgNw8j8U7jjSQ4GVGWSyrnPTwp0s88O+9OxTwX/dOcHYjOL/wl+LIWHbk/a6+soUsYahhJ9X6E… - smtpapi:
k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDPtW5iwpXVPiH5FzJ7Nrl8USzuY9zqqzjE0D1r04xDN6qwziDnmgcFNNfMewVKN2D1O+2J9N14hRprzByFwfQW76…
selectors probed - selector1:
Certificates
Loading certificate
HTTP security headers
- present
-
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- missing HSTS
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Permissions Policy
Header values
- referrer-policy
no-referrer-when-downgrade- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
font-src *.klarnacdn.net *.klevu.com *.ksearchnet.com *.fontawesome.com maxcdn.bootstrapcdn.com data: use.typekit.net *.criteo.com *.hotjar.com *.hotjar.io fonts.gstatic.com cdn.giosgusercontent.com media.flixcar.com media.flixfacts.com *.cdnfonts.com *.playable.com www.tokmanni.fi data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com sign.visma.net *.solteqcloud.com test1.maksuturva.fi payments.maksuturva.fi www.maksuturva.fi *.facebook.com *.facebook.net *.azureedge.net *.b2clogin.com *.onnistuu.fi *.tokmanni.fi www.tokmanni.fi 'self' 'unsafe-inline'; frame-ancestors www.tokmanni.fi 'self'; frame-src bid.g.doubleclick.net www.googletagmanager.com www.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com *.weltpixel.com js.klarna.com sdx.microsoft.com amc.demdex.net js.playground.klarna.com *.kustom.co js.playground.kustom.co *.google.com e.issuu.com *.
Links to (13)
- facebook.com×1
- finnkino.fi×1
- gogift.io×1
- incy.io×1
- instagram.com×1
- linkedin.com×1
- op.fi×1
- pinterest.com×1
- scanmarket.com×1
- tiktok.com×1
- tokmannigroup.com×1
- x.com×1
- youtube.com×1