varberg.se
HTML metadata
Technology
- Stack
- Java
Third-party hosts loaded (1)
- storage.gra.cloud.ovh.net×1
Contact
- Phone
DNS records live
- NS
-
- ns1-01.azure-dns.com
- ns2-01.azure-dns.net
- ns3-01.azure-dns.org
- ns4-01.azure-dns.info
- MX
-
- 10 varberg-se.mail.protection.outlook.com
Email authentication strong
- SPF
-
v=spf1 include:spf.protection.outlook.com include:all._spf.plma.se include:mail.sitevision-cloud.net include:spf.topdesk.net a:relay2.hostnet.se ip4:91.123.56.128 ip4:46.59.104.5 ip4:91.233.50.120 ip4:91.233.50.96 ip4:185.5.21.100 -allstrict (-all) - DMARC
-
v=DMARC1; p=reject; rua=mailto:dmarc@varberg.sepolicy: reject (enforced) - DKIM
-
- selector2:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCk4vnBBZyPvCVLn3dNZCG6bH+jbTYMNgfgSGNUI8vnTJu8oKD7UjDZpZdQfRP0SHhEn0aGa6IJnQOUkzAOCF…
selectors probed - selector2:
Certificate (current)
R13
Expires in 41 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Permissions Policy
Header values
- referrer-policy
no-referrer- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src 'none'; script-src 'unsafe-inline' 'unsafe-eval' https://varberg.se/ https://tse-varberg.sitevision-cloud.se/; style-src 'unsafe-inline' https://varberg.se/ https://tse-varberg.sitevision-cloud.se/ https://karta.varberg.se/ https://storage.gra.cloud.ovh.net/ https://mfstatic.com/css/mediaflowplayer.min.css; object-src 'none'; base-uri 'self'; connect-src 'self' https://svanalytics.containers.piwik.pro/ https://svanalytics.piwik.pro/ https://storage.gra.cloud.ovh.net/ https://ebbot.eu/ wss://ebbot.eu/api/ https://m.mediaflow.com/ https://mfstatic.com/ https://maps.googleapis.com/ https://api.kolada.se/ https://stats.mediaflow.com/ https://*.mediaflow.com/; frame-ancestors 'none'; font-src 'self' https://storage.gra.cloud.ovh.net/ https://mfstatic.com/ data:; frame-src 'self' https://karta.varberg.se/; img-src 'self' https://storage.gra.cloud.ovh.net/ https://assets.mediaflowpro.com/ https://oppnadata.skr.se/ https://oppnadata.skl.se/; manifest-src 'self'; media-src 'self'- strict-transport-security
max-age=31536000; preload