Good
Looks good from the outside.
pianola.se
95 out of 100 points. 1 thing to fix or review.
Checked just now, live against public data.
DKIM
Could not find DKIM using common selectors. It may exist on a custom selector we did not guess.
How to fix it: Enable DKIM signing with your mail provider (for Microsoft 365: turn on DKIM in the Defender portal).
No records in the answer.
DMARC
DMARC rejects spoofed mail (p=reject), the strongest level.
_dmarc.pianola.seTXTv=DMARC1; p=reject; pct=100; rua=mailto:gdpr@lumrait.se; ruf=mailto:gdpr@lumrait.se; fo=1
SPF
SPF is present and hard-fails everything outside the list (-all).
pianola.seTXTv=spf1 -all
Name servers (NS)
2 name servers, which gives redundancy if one stops responding.
pianola.seNSricardo.ns.cloudflare.compianola.seNSulla.ns.cloudflare.com
SOA (zone base data)
The zone is managed by ricardo.ns.cloudflare.com, contact dns.cloudflare.com.
pianola.seSOAricardo.ns.cloudflare.com dns.cloudflare.com 2415160372 10000 2400 604800 1800
Address (A/AAAA)
The domain points to a server (2 IPv4, 2 IPv6).
pianola.se225
TLS certificate
Valid certificate, expires in 87 days.
pianola.seCERT subjectpianola.sepianola.seCERT issuerLet's Encrypt (YE1)pianola.seCERT notBeforeSep 17 18:52:18 2026 GMTpianola.seCERT notAfterDec 16 18:52:17 2026 GMTpianola.seTLS protocolTLSv1.3
Security headers
The website sets all important security headers (HSTS, CSP and more).
HSTSHTTP headermax-age=31536000; includeSubDomains; preloadContent-Security-PolicyHTTP headerdefault-src 'self'; script-src 'self' 'sha256-18bQLzesBtRMN3fX96XgHJQWqElbs7G3OKcsOWW0bis=' 'sha256-7k8SXWRfpk9juSjkyTK55VX5j/xVkv3fdnW67Fy/15Y=' 'sha256-Bd36S7YTJaBwsrXbllK4m1g2V6IhKXChTwrw/ZhRhUg=' 'sha256-cmJDeq6Yii5gBnsU/ihmfCtNgNaZRxNSnkkWS3sM4ZI=' 'sha256-lo3ylQh0/p9TPcN0r02GuHy8JxKhRoZeSoEWOW9wK5U=' 'sha256-p7VYiv/er6Hx87GvYMynqQ8ESxQ8d1yPcT/xB47HoFE=' 'sha256-viLf40yUjQRekFs28Ek3C9oB58qUuvxB8FdUmwVkCqE=' 'sha256-wLuPuB4GSaRYvCQ57p0coON+NP8sZ1J059LfH/WhOR4='; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com; img-src 'self' data: blob: https:; font-src 'self' data: https:; connect-src 'self' https:; frame-ancestors 'none'; object-src 'none'; base-uri 'self'; form-action 'self'; upgrade-insecure-requests
Since 30 August 2026 the grade is calculated in one combined way. Previously shared links may show a different number.
Put the badge on your site or in your email signature. It links back here so anyone who clicks sees the full result.
<a href="https://kollen.lumrait.se/en/resultat?domain=pianola.se" rel="noopener"><img src="https://kollen.lumrait.se/api/badge?domain=pianola.se" alt="Checked by KOLLEN, grade A" width="204" height="28"></a>The badge updates daily. If the grade drops it only shows "Checked by KOLLEN" until it is fixed.
MX (mail reception)
Mail is handled by another provider ().
pianola.seMX0
Blacklist
The domain's IP address (104.21.61.178) is not listed (checked SpamCop, Spamhaus, Barracuda).
pianola.seA104.21.61.178104.21.61.178DNSBLSpamCop: not listed104.21.61.178DNSBLSpamhaus: not listed104.21.61.178DNSBLBarracuda: not listed
SPF tree2026-09-20 10:23:01 UTC
DNS lookups when the record is followed: 0 of 10
pianola.se → v=spf1 -all
DMARC interpretation
v=DMARC1; p=reject; pct=100; rua=mailto:gdpr@lumrait.se; ruf=mailto:gdpr@lumrait.se; fo=1gdpr@lumrait.se · reports go to a third party (lumrait.se)gdpr@lumrait.seDNSSEC
DNSSEC is enabled; DNS responses are signed and harder to forge.
pianola.se.3600DS2371 13 2 49D49C980EAA0D0583A4D1F6BAFCF069A6F5E7A2209EDCDCE29C1E5B9678A762
CAA (certificate authorities)
CAA records exist, which restricts who may issue certificates for the domain.
pianola.seCAA0 issue "digicert.com; cansignhttpexchanges=yes"pianola.seCAA0 issuewild "comodoca.com"pianola.seCAA0 issue "comodoca.com"pianola.seCAA0 issue "pki.goog; cansignhttpexchanges=yes"pianola.seCAA0 issue "letsencrypt.org"pianola.seCAA0 issuewild "letsencrypt.org"pianola.seCAA0 iodef "mailto:support@lumrait.se"pianola.seCAA0 issuewild "digicert.com; cansignhttpexchanges=yes"pianola.seCAA0 issuewild "pki.goog; cansignhttpexchanges=yes"pianola.seCAA0 issuewild "ssl.com"pianola.seCAA0 issue "ssl.com"
Domain age
Established domain, registered 2026-04-23 (5 months old). Age is no guarantee, but freshly registered scam domains are filtered out here.
pianola.seWHOIS created2026-04-23T00:00:00.000Z
Subdomain takeover
No takeover-able subdomains were found among the 14 common ones we tested.
No records in the answer.
Security headers with values2026-09-20 10:23:01 UTC
GET https://pianola.se/ → HTTP 200
max-age=31536000; includeSubDomains; preloadmax-age at least one year, includeSubDomains and preload.default-src 'self'; script-src 'self' 'sha256-18bQLzesBtRMN3fX96XgHJQWqElbs7G3OKcsOWW0bis=' 'sha256-7k8SXWRfpk9juSjkyTK55VX5j/xVkv3fdnW67Fy/15Y=' 'sha256-Bd36S7YTJaBwsrXbllK4m1g2V6IhKXChTwrw/ZhRhUg=' 'sha256-cmJDeq6Yii5gBnsU/ihmfCtNgNaZRxNSnkkWS3sM4ZI=' 'sha256-lo3ylQh0/p9TPcN0r02GuHy8JxKhRoZeSoEWOW9wK5U=' 'sha256-p7VYiv/er6Hx87GvYMynqQ8ESxQ8d1yPcT/xB47HoFE=' 'sha256-viLf40yUjQRekFs28Ek3C9oB58qUuvxB8FdUmwVkCqE=' 'sha256-wLuPuB4GSaRYvCQ57p0coON+NP8sZ1J059LfH/WhOR4='; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com; img-src 'self' data: blob: https:; font-src 'self' data: https:; connect-src 'self' https:; frame-ancestors 'none'; object-src 'none'; base-uri 'self'; form-action 'self'; upgrade-insecure-requestsPartial: unsafe-inline.nosniffnosniffstrict-origin-when-cross-originDoes not leak the path to other domains.SAMEORIGIN (CSP frame-ancestors 'none')Framing is controlled via CSP frame-ancestors, the modern form.accelerometer=(), ambient-light-sensor=(), autoplay=(), battery=(), camera=(), display-capture=(), document-domain=(), encrypted-media=(), fullscreen=(self), geolocation=(), gyroscope=(), magnetometer=(), microphone=(), midi=(), payment=(), picture-in-picture=(), publickey-credentials-get=(), screen-wake-lock=(), sync-xhr=(), usb=(), web-share=(), xr-spatial-tracking=()Bonus: restricts camera, microphone, location and more.same-originBonus: isolates the window from other origins.The grading here is information only. The grade above still only counts whether the header exists.