vantaa.fi
HTML metadata
Technology
- CMS
- Drupal
- Analytics
-
- Google Tag Manager
- Fonts
-
- Google Fonts
Third-party hosts loaded (5)
- eum.instana.io×1
- fonts.googleapis.com×1
- play2.qbrick.com×1
- static.addtoany.com×1
- www.googletagmanager.com×1
Social
Contact
- Phone
DNS records live
- NS
-
- ns1.plat.fi
- ns2.plat.fi
- ns3.plat.fi
- ns4.plat.fi
- ns5.plat.fi
- MX
-
- 0 vantaa-fi.mail.protection.outlook.com
- TXT
-
atlassian-sending-domain-verification=a48b2e63-aeea-479d-b9ee-337cc95deff0NsUqyb3zsE9A1csYlD0DA2xON81qbAGtmrf/TPGxwqp2PcU4Ff6bOyEUwTahxhjccbbe7OQQVRH6hVM5iG+yEA==
- Verified for
-
- Atlassian
- Meta
- Microsoft 365
Email authentication strong
- SPF
-
v=spf1 a:c.spf.service-now.com a:d.spf.service-now.com include:spf.logiacloud.fi include:spf.protection.outlook.com include:mail.webropolsurveys.com include:spf.a.vantaa.fi include:_spf.questback.com include:spf.lianamailer.com ip4:81.22.248.64 ip4:80.242.30.39 ip4:195.10.162.76/32 ip4:213.214.155.0/24 ip4:81.22.164.56/30 ip4:95.175.113.181 ip4:89.250.48.136 ip4:193.64.173.33 -allstrict (-all) - DMARC
-
v=DMARC1; p=reject; rua=mailto:6eo27m4v@ag.eu.dmarcadvisor.com;policy: reject (enforced) - DKIM
-
Show 5 DKIM selectors
- default:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQC4o/hWgnIW9SKjb6HWNhxi/MhHRjoEjVt8Z4N+3N5U4qPJNPEOkAxRvBJqh3OlhWqgezAiC1unbikiVVtFQT… - selector1:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAqn2sfZyn5hs3Xs9fgYtGeDXpOZ5KPpkFI4sdYzcn4kBTyOiz5btZIfBUEScRbom2I9gs+pxEELy2Mt… - selector2:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDwh5HMo60Tp02S1lvtxPNb/xV+J3kEr/TgdomHBS/ttvtzQ6lcOiHdHb+jyZoM9EHSFMRmcaqXKwJqYDAqib… - s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAudki7QyV1z/tTrdDt+YQJlCp2o0shtrWidr4rzU52MHv8/ndXTuDGOWkyc32/LMecuJ+1H6EyLYM4pJmfi… - s2:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA0WwyO9w326e230V0julxj7QTFVtB8zpf1f1WAzM6yW88VoafzWbci2IJSMyX5oc1/g/yLZQ0BWwr5IdzjY…
selectors probed - default:
Certificate (current)
Entrust OV TLS Issuing RSA CA 2
Expires in 296 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Permissions Policy
Header values
- referrer-policy
no-referrer, strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
upgrade-insecure-requests; default-src https: data: 'unsafe-inline' 'unsafe-eval'; frame-ancestors 'self'; base-uri 'self' *.qbrick.com; media-src * blob:; worker-src * blob:; object-src 'self'; connect-src wss: https:- strict-transport-security
max-age=31557600