tv4play.se

.se crawl

First seen 2026-05-19 · Last seen 2026-05-30 · ok HTTP/1.1 200 3188 ms crawled 2026-05-30

US · 13.33.235.98 · AS16509 Amazon.com, Inc.

Reputation 100/100

Classifying

HTML metadata

Title
TV4 Play | Hela Sveriges streamingtjänst
Description
Streama program, reality, underhållning, sport, filmer, serier och mycket mer på TV4 Play!
Language
sv
Canonical
https://www.tv4play.se

Open Graph

url
https://www.tv4play.se
title
TV4 Play | Hela Sveriges streamingtjänst
description
Streama program, reality, underhållning, sport, filmer, serier och mycket mer på TV4 Play!

Technology

CDN
Amazon CloudFront
CMS
Next.js
JS framework
Next.js

Third-party hosts loaded (4)

  • imageproxy.a2d.tv×1
  • nordic-gateway.tv4.a2d.tv×1
  • payment-gateway.tv4.commercial.a2d.tv×1
  • sessions.bugsnag.com×1

Contact

Phone

DNS records live

NS
  • ns-1150.awsdns-15.org
  • ns-1787.awsdns-31.co.uk
  • ns-386.awsdns-48.com
  • ns-806.awsdns-36.net
MX
  • 0 tv4play-se.mail.protection.outlook.com
  • 40 email-smtp.eu-west-1.amazonses.com
TXT
  • amazonses:wU8bDBCz+6WiV6G8sskehHS02EjJwquCGRttXBOr5Ps=
Verified for
  • Google
  • Microsoft 365
  • Notion

Email authentication strong

SPF
v=spf1 a:mail1.releasy.se a:mail2.releasy.se include:amazonses.com include:spf.protection.outlook.com ~all
softfail (~all)
DMARC
v=DMARC1; p=reject; sp=reject; fo=1; rua=mailto:rhisqdsk@ag.eu.dmarcian.com,mailto:dmarc.reports.se@tv4play.se; ruf=mailto:dmarc.fails.se@tv4play.se;
policy: reject (enforced) · sp=reject
DKIM
  • selector1: v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA446/YNXNJIr+op2+ovEZJYokqUEby5frmGlnLFYYsZCF4Ny75NxcNgo2LLsKgWxFivhED2tAbWZJ2j…
  • selector2: v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA3EazLddmrRZRI0gfFoDj7WebHo0f52qyzfCxHzsiTjrAf/KtDcuMa/8GBaHovl5nDXQGnXiZwaS2Vh…
selectors probed

Certificate (current)

Amazon RSA 2048 M04
from 2026-05-19 to 2026-12-03
Expires in 185 days

HTTP security headers

Header hygiene 90/100 Checked live page: https://www.tv4play.se/

present
  • strict-transport-security
  • content-security-policy
  • x-frame-options
  • x-content-type-options
  • referrer-policy
  • permissions-policy
  • cross-origin-opener-policy
  • cross-origin-resource-policy
findings
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
Header values
referrer-policy
no-referrer
x-frame-options
SAMEORIGIN
permissions-policy
attribution-reporting=(self "https://quantserve.com" "https://pixel.quantserve.com" "https://quantcast.com" "https://quantcount.com")
x-content-type-options
nosniff
content-security-policy
default-src 'self' blob: *;base-uri 'self';font-src 'self' data: https://apps.mypurecloud.com/ https://chat.kindlycdn.com/ https://cdn.braze.eu https://use.fontawesome.com;form-action 'self' *;frame-ancestors 'self' *;img-src 'self' data: *;object-src 'none';script-src 'self' 'unsafe-inline' 'unsafe-eval' *;script-src-attr 'none';style-src 'self' 'unsafe-inline' *;worker-src 'self' blob:
strict-transport-security
max-age=15552000; includeSubDomains
cross-origin-opener-policy
same-origin
cross-origin-resource-policy
same-origin

Links to (5)

Linked from (12)