unionensakassa.se
HTML metadata
Technology
Third-party hosts loaded (1)
- pages.inoviaai.se×1
DNS records live
- NS
-
- ns1-06.azure-dns.com
- ns2-06.azure-dns.net
- ns3-06.azure-dns.org
- ns4-06.azure-dns.info
- MX
-
- 0 unionensakassa-se.mail.protection.outlook.com
- TXT
-
imoj87un0an5b4r0tfhuevj8hoko0pnj7icl7dfen3n550n8ma1have-i-been-pwned-verification=7bf4bdf612b3cec487c15ff8b9a7d953
- Verified for
-
- 1Password
- Apple
- Microsoft 365
Email authentication strong
- SPF
-
v=spf1 include:mail.webropolsurveys.com include:spf.protection.outlook.com include:_spf.easit.net include:_spf.softronic.se include:_spf.rulemailer.com a:goofy.dcp.se ip4:193.192.54.98 ip4:13.48.228.14 -allstrict (-all) - DMARC
-
v=DMARC1; p=quarantine; pct=100; rua=mailto:dmarc@unionensakassa.se; ruf=mailto:dmarc@unionensakassa.se; fo=1policy: quarantine - DKIM
-
- selector2:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDmm6ZYmCxBhZoTIYAd1Ditx0hf+sU3HyXqIeVhaL1eb7qPyiTnPm2PduE6I3/3S0+N/Jz/Uo9Yh1lh9d3xYQ… - dkim:
v=DKIM1;k=rsa;p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCwD/i8XUhszWZ4XRCq2EqkYq19WnuiO/RgNRBmXC87M84bkKxLBrBCfmibO6SbeAc0aZtRAhxHqk7XRwEZo2Oa…
selectors probed - selector2:
Certificate (current)
R12
Expires in 61 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
same-origin- x-frame-options
SAMEORIGIN- permissions-policy
accelerometer=(),autoplay=(),camera=(),display-capture=(),encrypted-media=(),fullscreen=(self "https://player.vimeo.com" "https://video.qbrick.com"),gamepad=("*"),geolocation=(),gyroscope=(),magnetometer=(),microphone=(),midi=(),payment=(),picture-in-picture=(self "https://player.vimeo.com" "https://video.qbrick.com"),publickey-credentials-get=(),sync-xhr=(self),usb=(),screen-wake-lock=(),xr-spatial-tracking=()- x-content-type-options
nosniff- content-security-policy
default-src 'none'; script-src 'self' 'nonce-5FowNNti4QhtxhoJwtP12zQfWTHYJHfqQFCZC3Bz8KI=' 'unsafe-inline' *.inoviaai.se *.vizzit.se *.readspeaker.com; style-src 'self' 'unsafe-inline' *.qbrick.com *.googleapis.com; img-src 'self' data:; font-src 'self' *.gstatic.com; connect-src 'self' *.qbrick.com *.inoviaai.se *.vizzit.se inoviaai.b2b.se wss://inoviaai.b2b.se; frame-src 'self' *.vimeo.com *.qbrick.com global.frcapi.com inoviaai.b2b.se; object-src 'none'; base-uri 'self'; form-action 'self'; media-src 'self' *.readspeaker.com;- strict-transport-security
max-age=31536000; includeSubDomains; preload