awb.nl
HTML metadata
Technology
- Stack
- Java
Third-party hosts loaded (2)
- cdn01l.vaillant-group.com×4
- cdn.consentmanager.net×1
DNS records live
- NS
-
- a.prim-ns.de
- a.sec-ns.net
- c.sec-ns.de
- m.sec-ns.de
- n.sec-ns.net
- MX
-
- 10 awb-nl.mail.protection.outlook.com
- TXT
-
vnzdb6d2mff6srmqg7sndhrhk2r9fvxlqRffqj8oUMTEkf70LE/JWfY5u/FZm+6V5WrpftZOLrrIUCVl0+IBptLnsaitHj3eW2FRrrde29fBg9MMjDFcsg==
- Verified for
-
- GlobalSign
- Microsoft 365
Email authentication weak
- SPF
-
v=spf1 mx ip4:57.66.132.25 ip4:57.66.132.26 ip4:57.66.132.12 ip4:57.66.211.122 ip4:57.66.211.126 ip4:57.66.211.130 ip4:57.66.211.134 include:spf.protection.outlook.com -allstrict (-all) - DMARC
- not published
- DKIM
- no key found at common selectors
Certificate (current)
GlobalSign GCC R6 AlphaSSL CA 2025
Expires in 64 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
no-referrer-when-downgrade- x-frame-options
SAMEORIGIN- permissions-policy
geolocation=(self "https://cat.vaillant.it" "https://cat.hermann-saunierduval.it")- x-content-type-options
nosniff- content-security-policy
default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' blob: cdn01l.vaillant-group.com *.adalyser.com *.adform.com *.adform.net *.adroll.com *.bing.com *.consentmanager.net *.contentsquare.net *.criteo.com *.doubleclick.net *.facebook.com *.facebook.net *.g.doubleclick.net *.glp8.net *.google.ad *.google.ae *.google.al *.google.am *.google.as *.google.at *.google.az *.google.ba *.google.be *.google.bf *.google.bg *.google.bi *.google.bj *.google.bs *.google.bt *.google.by *.google.ca *.google.cat *.google.cd *.google.cf *.google.cg *.google.ch *.google.ci *.google.cl *.google.cm *.google.cn *.google.co.ao *.google.co.bw *.google.co.ck *.google.co.cr *.google.co.id *.google.co.il *.google.co.in *.google.co.jp *.google.co.ke *.google.co.kr *.google.co.ls *.google.co.ma *.google.co.mz *.google.co.nz *.google.co.th *.google.co.tz *.google.co.ug *.google.co.uk *.google.co.uz *.google.co.ve *.google.co.vi *.google.co.za *.google.co.zm *.google.co.zw *.google.com *.google.com.af- strict-transport-security
max-age=63072000; preload