almelovoorelkaar.nl

.nl crawl

First seen 2026-06-02 · Last seen 2026-06-03 · ok HTTP/1.1 200 798 ms crawled 2026-06-03

US · 172.67.141.42 · AS13335 Cloudflare, Inc.

Reputation 94/100 dmarc monitor-only

Classifying

HTML metadata

Title
Almelovoorelkaar
Description
Op zoek naar passend vrijwilligerswerk of juist hulp nodig? Op Almelovoorelkaar.nl vind je elkaar gemakkelijk en veilig. Plaats ook je vraag en aanbod!
Language
nl

Open Graph

ttl
1440769
url
https://www.almelovoorelkaar.nl/
title
Hulp vragen of bieden als vrijwilliger
locale
nl_NL
site name
Almelovoorelkaar

Technology

CDN
Cloudflare
Analytics
  • Google Tag Manager

Third-party hosts loaded (2)

  • cdn.onesignal.com×1
  • www.googletagmanager.com×1

Social

DNS records live

NS
  • kellen.ns.cloudflare.com
  • nataly.ns.cloudflare.com
MX
  • 10 ci2dx0avd.mx.service.one

Email authentication partial

SPF
v=spf1 a ip4:213.171.128.32/29 ip4:213.171.129.32/29 ip4:84.20.5.128/27 ip6:2a00:1bd8:c:30::1:1/64 mx include:spf.mandrillapp.com include:_spf.hostnet.nl ~all
softfail (~all)
DMARC
v=DMARC1; p=none;
policy: none (monitoring only)
DKIM
  • default: v=DKIM1; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDKhgaLXwzNEbkmIIFXBsLSUrxEHk9bnfnLYooEgmEPK6S42VnTu5ZzL6P15rySkuKkyT4UW8JXx+mP6WsSGw5fPQYZK…
selectors probed

Certificate (current)

WE1
from 2026-04-05 to 2026-07-04
Expires in 29 days

HTTP security headers

Header hygiene 90/100 Checked live page: https://www.almelovoorelkaar.nl/

present
  • strict-transport-security
  • content-security-policy
  • x-frame-options
  • x-content-type-options
  • referrer-policy
  • permissions-policy
findings
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
Header values
referrer-policy
strict-origin-when-cross-origin
x-frame-options
SAMEORIGIN
permissions-policy
accelerometer=(), camera=(), document-domain=(), fullscreen=(self), geolocation=(), gyroscope=(), magnetometer=(), microphone=(), midi=(), payment=(), usb=(), sync-xhr=(self)
x-content-type-options
nosniff
content-security-policy
default-src 'self' data: ; script-src 'self' 'report-sample' 'unsafe-eval' 'unsafe-inline' *.cloudfront.net *.google-analytics.com ssl.google-analytics.com www.google.com www.googleadservices.com www.googleoptimize.com *.googletagmanager.com www.gstatic.com tagmanager.google.com maps.googleapis.com *.doubleclick.net connect.facebook.net *.landbot.io webchat.digitalcx.com *.hotjar.com cdnjs.cloudflare.com stackpath.bootstrapcdn.com cdn.jsdelivr.net code.jquery.com onesignal.com cdn.onesignal.com ads.creative-serving.com googleads.g.doubleclick.net *.monsido.com js-agent.newrelic.com bam.eu01.nr-data.net nonce-cea40538 ; style-src 'self' 'report-sample' blob: 'unsafe-inline' *.cloudfront.net fonts.googleapis.com cdn.jsdelivr.net onesignal.com cdn-images.mailchimp.com translate.googleapis.com *.landbot.io nonce-cea40538 ; img-src 'self' data: blob: ssl.gstatic.com www.gstatic.com *.google-analytics.com *.google.com *.google.nl *.google.de *.google.be *.g.doubleclick.net maps.gstatic.com *
strict-transport-security
max-age=63072000; includeSubDomains preload

Links to (8)

Linked from (1)