Good
Looks good from the outside.
lumrait.se
100 out of 100 points. Nothing urgent, a good level from the outside.
Checked just now, live against public data.
DMARC
DMARC rejects spoofed mail (p=reject), the strongest level.
_dmarc.lumrait.seTXTv=DMARC1; p=reject; pct=100; rua=mailto:rua@dmarc.brevo.com; adkim=r; aspf=r
SPF
SPF is present and hard-fails everything outside the list (-all).
lumrait.seTXTv=spf1 include:spf.protection.outlook.com include:spf.brevo.com -all
DKIM
DKIM found (selector "selector1", 2048-bit key). Outgoing mail can be signed and verified.
selector1._domainkey.lumrait.seTXTv=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA0ml9DOv+IpH5Rcg8DhyctiryyupgWfgb/eOyV0oAJ3iYWX7aUNrjEn9z2vMM8DdRGQREN9LEVuulYYCALwH0+86UPLs+BZ7gCV/LRnLlyo4Ru8jn/jNc+nFaIxcugi2foFUXsYLTc+sdmnAY3ekZk4Ynwlv7qWZ25gZ58iblVjovUySLqgHh8Qwsdy9AxXgMy2xddT2Urp0JdaJXd/mL6B1346+zc48Ox+tZoa+ewZ5X96OlQG0UtUi3H0jcJwEUFubOVSr70F8J8p0fwjulpg5e0xrdJgTJuJbC2x4XYkviF/LKRraX9iVyki1NMQk6mO4qdPOFHtuiUrkZT9KykQIDAQAB;
Name servers (NS)
2 name servers, which gives redundancy if one stops responding.
lumrait.seNSathena.ns.cloudflare.comlumrait.seNSalbert.ns.cloudflare.com
SOA (zone base data)
The zone is managed by albert.ns.cloudflare.com, contact dns.cloudflare.com.
lumrait.seSOAalbert.ns.cloudflare.com dns.cloudflare.com 2415304954 10000 2400 604800 1800
Address (A/AAAA)
The domain points to a server (2 IPv4, 2 IPv6).
lumrait.se300
TLS certificate
Valid certificate, expires in 87 days.
lumrait.seCERT subjectlumrait.selumrait.seCERT issuerLet's Encrypt (YE1)lumrait.seCERT notBeforeSep 18 00:50:58 2026 GMTlumrait.seCERT notAfterDec 17 00:50:57 2026 GMTlumrait.seTLS protocolTLSv1.3
Security headers
The website sets all important security headers (HSTS, CSP and more).
HSTSHTTP headermax-age=31536000; includeSubDomains; preloadContent-Security-PolicyHTTP headerdefault-src 'self'; script-src 'self' 'sha256-M0Vf4LnMGNUeekx4XarRq4tVNyzY0EqrjP6rEskOQok=' 'sha256-o07hqXq07RU7eAhydHxQ53Sr1gJtQz62u/+Q0Yfej7k=' 'sha256-zKZ0eYFCAe7X/q6jvHGpXt5RHGHFIavFwbZYSGEW2sM='; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com; img-src 'self' data: blob: https:; font-src 'self' data: https:; connect-src 'self' https:; frame-ancestors 'none'; object-src 'none'; base-uri 'self'; form-action 'self'; upgrade-insecure-requests
Since 30 August 2026 the grade is calculated in one combined way. Previously shared links may show a different number.
Put the badge on your site or in your email signature. It links back here so anyone who clicks sees the full result.
<a href="https://kollen.lumrait.se/en/resultat?domain=lumrait.se" rel="noopener"><img src="https://kollen.lumrait.se/api/badge?domain=lumrait.se" alt="Checked by KOLLEN, grade A" width="204" height="28"></a>The badge updates daily. If the grade drops it only shows "Checked by KOLLEN" until it is fixed.
This is everything that is visible from the outside. What decides whether a click becomes a breach, multi-factor, conditional access, sharing and apps, is only visible from the inside. That is what PIANOLA measures.
MX (mail reception)
Mail is handled by Microsoft 365 (lumrait-se.mail.protection.outlook.com).
lumrait.seMX1 lumrait-se.mail.protection.outlook.com
Blacklist
The domain's IP address (188.114.96.1) is not listed (checked Spamhaus, SpamCop, Barracuda).
lumrait.seA188.114.96.1188.114.96.1DNSBLSpamhaus: not listed188.114.96.1DNSBLSpamCop: not listed188.114.96.1DNSBLBarracuda: not listed
SPF tree2026-09-20 12:12:52 UTC
DNS lookups when the record is followed: 2 of 10 · own servers (a/mx/ip4/ip6) included
lumrait.se → v=spf1 include:spf.protection.outlook.com include:spf.brevo.com -allinclude:spf.protection.outlook.com → v=spf1 ip4:40.92.0.0/15 ip4:40.107.0.0/16 ip4:52.100.0.0/15 ip4:52.102.0.0/16 ip4:52.103.0.0/17 ip4:104.47.0.0/17 ip6:2a01:111:f400::/48 ip6:2a01:111:f403::/49 ip6:2a01:111:f403:8000::/51 ip6:2a01:111:f403:c000::/51 ip6:2a01:111:f403:f000::/52 -allinclude:spf.brevo.com → v=spf1 ip4:185.41.28.0/22 ip4:94.143.16.0/21 ip4:185.24.144.0/22 ip4:153.92.224.0/19 ip4:213.32.128.0/18 ip4:185.107.232.0/22 ip4:77.32.128.0/18 ip4:77.32.192.0/19 ip4:212.146.192.0/18 ip4:172.246.0.0/18 -all
DMARC interpretation
v=DMARC1; p=reject; pct=100; rua=mailto:rua@dmarc.brevo.com; adkim=r; aspf=rrua@dmarc.brevo.com · reports go to a third party (dmarc.brevo.com)DNSSEC
DNSSEC is enabled; DNS responses are signed and harder to forge.
lumrait.se.3600DS2371 13 2 AFE6844BB0755D977B42A19267F58CDDE461C36C0ECE7EF2E00D4F6CBEA5FD30
CAA (certificate authorities)
CAA records exist, which restricts who may issue certificates for the domain.
lumrait.seCAA0 issuewild "digicert.com; cansignhttpexchanges=yes"lumrait.seCAA0 issuewild "comodoca.com"lumrait.seCAA0 iodef "mailto:support@lumrait.se"lumrait.seCAA0 issuewild "pki.goog; cansignhttpexchanges=yes"lumrait.seCAA0 issue "letsencrypt.org"lumrait.seCAA0 issuewild "ssl.com"lumrait.seCAA0 issue "ssl.com"lumrait.seCAA0 issue "comodoca.com"lumrait.seCAA0 issuewild "letsencrypt.org"lumrait.seCAA0 issue "digicert.com; cansignhttpexchanges=yes"lumrait.seCAA0 issue "pki.goog; cansignhttpexchanges=yes"
Domain age
Established domain, registered 2026-01-21 (8 months old). Age is no guarantee, but freshly registered scam domains are filtered out here.
lumrait.seWHOIS created2026-01-21T00:00:00.000Z
Subdomain takeover
No takeover-able subdomains were found among the 14 common ones we tested.
No records in the answer.
Security headers with values2026-09-20 12:12:53 UTC
GET https://lumrait.se/ → HTTP 200
max-age=31536000; includeSubDomains; preloadmax-age at least one year, includeSubDomains and preload.default-src 'self'; script-src 'self' 'sha256-M0Vf4LnMGNUeekx4XarRq4tVNyzY0EqrjP6rEskOQok=' 'sha256-o07hqXq07RU7eAhydHxQ53Sr1gJtQz62u/+Q0Yfej7k=' 'sha256-zKZ0eYFCAe7X/q6jvHGpXt5RHGHFIavFwbZYSGEW2sM='; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com; img-src 'self' data: blob: https:; font-src 'self' data: https:; connect-src 'self' https:; frame-ancestors 'none'; object-src 'none'; base-uri 'self'; form-action 'self'; upgrade-insecure-requestsPartial: unsafe-inline.nosniffnosniffstrict-origin-when-cross-originDoes not leak the path to other domains.SAMEORIGIN (CSP frame-ancestors 'none')Framing is controlled via CSP frame-ancestors, the modern form.accelerometer=(), ambient-light-sensor=(), autoplay=(), battery=(), camera=(), display-capture=(), document-domain=(), encrypted-media=(), fullscreen=(self), geolocation=(), gyroscope=(), magnetometer=(), microphone=(), midi=(), payment=(), picture-in-picture=(), publickey-credentials-get=(), screen-wake-lock=(), sync-xhr=(), usb=(), web-share=(), xr-spatial-tracking=()Bonus: restricts camera, microphone, location and more.same-originBonus: isolates the window from other origins.The grading here is information only. The grade above still only counts whether the header exists.