upplandsmuseet.se

.se crawl

First seen 2026-05-12 · Last seen 2026-05-18 · ok HTTP/1.1 200 16141 ms crawled 2026-05-18

SE · 147.78.228.149 · AS57773 1Access Sweden AB

Reputation 92/100 no dmarc policy

sector nonprofit type homepage

HTML metadata

Title
Upplandsmuseet
Description
Välkommen till ett kulturhistoriskt museum mitt i Uppsala! Här får du en kunskapsupplevelse – ett möte med Upplands kulturarv. Hos oss hittar du intressanta utställningar, aktiviteter för alla åldrar, butik och café. Vi finns i Akademikvarnen i centrala Uppsala, i Gamla Uppsala Museum och på friluftsmuseet Disagården.
Language
sv
Canonical
http://www.upplandsmuseet.se/
Translations
  • ar
  • de
  • en
  • fa
  • fi
  • sv

Open Graph

url
https://www.upplandsmuseet.se/
title
Upplandsmuseet
description
Välkommen till ett kulturhistoriskt museum mitt i Uppsala! Här får du en kunskapsupplevelse – ett möte med Upplands kulturarv. Hos oss hittar du intressanta utställningar, aktiviteter för alla åldrar, butik och café. Vi finns i Akademikvarnen i centrala Uppsala, i Gamla Uppsala Museum och på friluftsmuseet Disagården.

Technology

Server
Microsoft-IIS
CMS
Gatsby
Analytics
  • Google Tag Manager
Social widgets
  • Disqus

Third-party hosts loaded (5)

  • cdn-eu.readspeaker.com×1
  • cdn.cookietractor.com×1
  • upplandsmuseetweb.disqus.com×1
  • www.google.com×1
  • www.googletagmanager.com×1

Social

Contact

Phone

DNS records live

NS
  • ns1.vmar.se
  • ns2.vmar.se
MX
  • 0 upplandsmuseet-se.mail.protection.outlook.com
TXT
  • xt12wvr5r7nm4q3nmrqmc7mzkp7jb04f
  • 6t5p5vgugmejn6024shp405ejc
Verified for
  • GlobalSign
  • Google
  • Microsoft 365

Email authentication weak

SPF
v=spf1 mx a ip4:94.255.220.21/32 include:spf.protection.outlook.com include:spf.multinet.com include:turbo-smtp.com ~all
softfail (~all)
DMARC
not published
DKIM
no key found at common selectors

Certificates

Loading certificate

HTTP security headers

Header hygiene 85/100 Checked live page: https://www.upplandsmuseet.se/

present
  • strict-transport-security
  • content-security-policy
  • content-security-policy-report-only
  • x-frame-options
  • x-content-type-options
  • referrer-policy
findings
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
  • missing Permissions Policy
Header values
referrer-policy
strict-origin-when-cross-origin
x-frame-options
DENY
x-content-type-options
nosniff
content-security-policy
default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes' https://ajax.googleapis.com https://code.jquery.com https://maxcdn.bootstrapcdn.com https://netdna.bootstrapcdn.com https://www.googletagmanager.com https://www.google-analytics.com https://region1.google-analytics.com https://stats.g.doubleclick.net https://cdn.readspeaker.com https://cdn-eu.readspeaker.com https://*.disqus.com https://*.fontawesome.com https://cdn.cookietractor.com; style-src 'self' 'unsafe-inline' https://*.fontawesome.com https://cdn.readspeaker.com https://cdn-eu.readspeaker.com; font-src 'self' https://*.fontawesome.com data:; img-src 'self' data: https://www.google-analytics.com https://*.disqus.com https://cdn-eu.readspeaker.com; connect-src 'self' https://www.google-analytics.com https://stats.g.doubleclick.net https://region1.google-analytics.com https://app.cookietractor.com; frame-src 'self' https://*.disqus.com https://www.youtube.com https://www.google.com; frame-ancestors
strict-transport-security
max-age=31536000; includeSubDomains; preload
content-security-policy-report-only
default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes' https://ajax.googleapis.com https://code.jquery.com https://maxcdn.bootstrapcdn.com https://netdna.bootstrapcdn.com https://www.googletagmanager.com https://www.google-analytics.com https://region1.google-analytics.com https://stats.g.doubleclick.net https://cdn.readspeaker.com https://cdn-eu.readspeaker.com https://*.disqus.com https://*.fontawesome.com https://cdn.cookietractor.com; style-src 'self' 'unsafe-inline' https://*.fontawesome.com https://cdn.readspeaker.com https://cdn-eu.readspeaker.com; font-src 'self' https://*.fontawesome.com data:; img-src 'self' data: https://www.google-analytics.com https://*.disqus.com https://cdn-eu.readspeaker.com; connect-src 'self' https://www.google-analytics.com https://stats.g.doubleclick.net https://region1.google-analytics.com https://app.cookietractor.com; frame-src 'self' https://*.disqus.com https://www.youtube.com https://www.google.com; frame-ancestors

Links to (7)

Linked from (2)