baarn.nl
HTML metadata
Technology
- CMS
- Drupal
- JS framework
- Next.js
Third-party hosts loaded (2)
- cuatro.sim-cdn.nl×64
- baarn.logging.simanalytics.nl×1
Social
DNS records live
- NS
-
- nsauth1.bit.nl
- nsauth2.bit.nl
- nsauth3.bit.org
- MX
-
- 100 baarn-nl.d-v1.mx.microsoft
- TXT
-
Show 37 TXT records
02beaa41d7d74e8970a0d0e9596d9ba8d4d5f519ce17dde80a1661fc39b840dc41d2f299e159448ed062793434a8ab085e87fc75d6a712e46fda3d5d6b8c43922627f1e9cc70b890fa2a492bd2f4bc8c603a705d54c266bf320e624f31d6963aGkEpK87BmFmePQtxwCmeguxXCXi0kWi3scG9TBxPEO8K3syBPj17TKejiWz55oEPbzDzrh2SWtknfIa43ghl9hGzqsAvzMy6tFv7SGCcYRzB6gJckrSjoh4B3e525zYq59c537ca864fec1c47db69642bc964be15de1baec4195b71724e09d19d759d82M5ubKfyX4z2VlHbGLkLX9S8H8aJHzrRL2IB7QoyPlBClOCM86IxGW7ATeeSkGqK6DomainVerification=6UE6HJYXG8HFGNP8U762J6Z38LZWAHAO901UUCZKLZUZ3B0RJ71CBA6S3UOLM4DAvws81tvwwb59nnw59hshlqpr29cfx3vmuRmex7cIXHEdLy+V73SJ1yLpuZdRwDSSkwb62roDd4s=a8608a0e92c4dd66869d703b9784f281aee6be9602f7f4fdc962af6392f99fd169shk9xr44ts6g5hwp2tkht0gss8zqbcDomainVerification=06JYU1HY39STJYTZ5ITCZKN915E8NDJCUYXKPI7886Z232Q7JS4WT78BKN93GOP7cGyeX5zcgArOuj6otJPs42hccPx0tRNYlAQVLwc4mzXIzbvXLhxFCyGov7nqVnbBRFelLUifml9UekjmJwciA7zACWVqFcDUPl6opRbQklKXHIg3a7GUrMatDaLr8VacTO1YZSLaUhEE3Tc8NU0BaRbYah4VKA5oHP9fyoRXbNZzr/F99R255mTBpQGI4KLybXnux603Sjm4yxvl6fdQyg==a3c21d18ab98b50adc6ff797978dd82bdc62266da570cea81243486c27255118android-enroll TXT https://msp.axle-it.nl/rtc/mspldms01/MDM/api/v1/enroll/AndroidEnroll3bc1a7356efe6a68620525ce9d22e2d91377683fa19c0a2f1a2a548eaf90ec2b05d346aa7c280d8419b52b63f336937878dd1c564bc6ae7acbf5be202261e3fd2e5697d5b00611e7256ac248712a76d5b44343bd1ec7516f80d5f44ca3566c44dU7U9qUw0AHWcYzk7KYo5fwWb4L0do4Vwy2NDuSmXdiwMkVImBzLaaRoXR5lOYsFrG5aXK4KvazOfDAfY1FNHPL96gFgDuLhWPl39XASdcR73ueubmOBhA8wWIrBfO3r8554735d9eefd7cac1e4cb13a57c42f6ae4e06dfe4c45e90d149bdbde0c44884d347381641d52aceb1fe580b5d49ddb8bf250400d29c8c7ca1a33e3eb64072cfprr1MiP8UfehzN2jGOciC7nbKsdTCAiBzMHUv56RZludEatox3yGtwNbTEUqS9IuL86ghUrAiVnMbb7lR9pOHA3bZXmE3X8YJ2MHrdWMGaMjguV3wurEOYnL5rUiSzz3HgrnVRyedrKu4LGEgF3tfPUV7s8ihVU0Xwta6VY3TplfLmFSnINoKgcNIyFdNtnb47bmwk8qgprwdqyb6xfbt65d8j0p45dvr4m8yxqnx9dlg35l4h8kytxkct97hsqw4f706701845b42ba474d3ed5b2d0ef900868ac8130090f59e43d77eb6905d5c9QaXzCYyqhFJFojx9smoNQ3gbTz0u2EfjytdsU5cvXo3SL2ihjdI3yaoJJ85DDNJPXHA5Bgkum2sLbVoTMscbNHpzFsS7VarvIUuVP1p7sHqn3Ut07y3DsSRDataxrL169i9nqvq0ixwUVIWX0fxF5jEJQEwpn3SfJTJlvBEiY+yirpAI9K9N2ki9R7K4TL4RDMYGYBVeDEidJP8xJt0phw==ios-enroll TXT https://msp.axle-it.nl/rtc/mspldms01/MDM/api/v1/enroll/IosEnroll21591932be554af826ee97f3548f71ddc5c5a9d4c2316c39d6099cfa7e8bce1a96828863f68fe9fb69825c964b03b2ae381da34a18b6c1117421e8fe77f2bf97
- Verified for
-
- Brevo
- Microsoft 365
Email authentication no MX
- SPF
- not published
- DMARC
- not published
- DKIM
- no key found at common selectors
Certificate (current)
Thawte TLS RSA CA G1
Expires in 234 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- content-security-policy-report-only
- x-content-type-options
- referrer-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing frame protection
- missing Permissions Policy
Header values
- referrer-policy
same-origin- x-content-type-options
nosniff- content-security-policy
default-src 'self'; img-src * data: 'unsafe-inline' blob:; style-src * 'unsafe-inline' blob:; font-src * data:; script-src * 'unsafe-inline' 'unsafe-eval'; connect-src *; form-action *; media-src *.readspeaker.com *.streamlock.net *.archieven.nl storage.googleapis.com scribit-pro-hosting.storage.googleapis.com scribit-pro.storage.googleapis.com app.talkjs.com *.bbvms.com *.cloudfront.net data: 'self' blob:; frame-src *; frame-ancestors 'self' https://*.polly.help; worker-src * 'unsafe-inline' blob:;- strict-transport-security
max-age=31536000- content-security-policy-report-only
default-src 'self'; img-src * data: blob:; style-src * 'unsafe-inline' blob:; font-src 'self' data: https://fonts.bunny.net https://fonts.gstatic.com https://cuatro.sim-cdn.nl https://cuatro.sim-cdn-acceptatie.nl https://cuatro.sim-cdn-test.nl; script-src 'nonce-N2NlYTRkM2MtODQyMi00YWUwLWE3ZTEtNmVkZWIxODVmMWJi' 'strict-dynamic' 'report-sample'; connect-src *; form-action 'self'; media-src https://*.readspeaker.com https://*.streamlock.net https://storage.googleapis.com https://scribit-pro-hosting.storage.googleapis.com https://scribit-pro.storage.googleapis.com https://app.talkjs.com 'self' blob:; frame-src *; frame-ancestors 'self' https://*.polly.help; worker-src * 'unsafe-inline' blob:; report-uri /api/csp-report