beterhoren.nl
HTML metadata
Technology
- Server
- Apache
- CMS
- Joomla
Third-party hosts loaded (4)
- www.amplifon.com×11
- assets.adobedtm.com×1
- www.gaes.es×1
- www.minisom.pt×1
Social
DNS records live
- NS
-
- ns-1314.awsdns-36.org
- ns-1615.awsdns-09.co.uk
- ns-204.awsdns-25.com
- ns-652.awsdns-17.net
- MX
-
- 10 mxa-00677301.gslb.pphosted.com
- 10 mxb-00677301.gslb.pphosted.com
- TXT
-
spycloud-domain-verification=7489d655-b78d-461c-a0b7-5be82c1bfd56amazonses:03Xq04d69A88UHE56LWBCpi1drnAVgklZzIXgeTRTGg=dtm-domain-verification=vHa35wLzoHdWY0rNflKMVtqhSs3hltuUHhvbodW6Zk8
- Verified for
-
- Apple
- Meta
- Microsoft 365
Email authentication strong
- SPF
-
v=spf1 ip4:160.8.44.19/32 ip4:160.8.44.20/31 ip4:194.79.58.54 ip4:194.79.58.55 ip4:92.42.235.1/24 ip4:92.42.239.114/32 ip4:92.42.239.248/32 include:spf.protection.outlook.com include:spf.mailtopay.nl include:musvc.com include:mail.zendesk.com include:spf.steam-connect.com -allstrict (-all) - DMARC
-
v=DMARC1; p=reject; rua=mailto:dmarc@amplifon.compolicy: reject (enforced) - DKIM
- no key found at common selectors
Certificate (current)
GeoTrust TLS RSA CA G1
Expires in 85 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- weak content type protection
- missing Permissions Policy
Header values
- referrer-policy
strict-origin-when-cross-origin, strict-origin-when-cross-origin- x-frame-options
DENY- x-content-type-options
nosniff, nosniff- content-security-policy
default-src 'self' 'unsafe-inline' 'unsafe-hashes' 'unsafe-eval' *.sendtportal.com *.adobedc.net *.omtrdc.net crosswordlabs.com *.linkedin.com *.licdn.com *.contentsquare.net *.yextevents.com *.sitescdn.com *.sitescdn.net *.fonts.gstatic.com *.everesttech.net; script-src-elem 'self' 'unsafe-inline' *.sendtportal.com *.scene7.com *.licdn.com *.contentsquare.net *.sitescdn.net *.sitescdn.com *.yextevents.com *.gstatic.com *.taboola.com *.beterhoren.nl *.google.com *.aiaibot.com *.clarity.ms *.doubleclick.net *.logbor.com *.realytics.net *.metaffiliation.com *.realytics.io *.googleadservices.com *.pinterest.com *.pinimg.com *.iadvize.com *.zemanta.com *.adroll.com *.adform.net *.bing.com *.monsido.com *.tiktok.com *.outbrain.com *.hotjar.com *.adalyser.com *.responsetap.com *.exelator.com *.trustpilot.com *.adnxs.com *.crwdcntrl.net *.teads.tv *.googleapis.com *.facebook.net *.google-analytics.com maps.googleapis.com *.amplifon.com *.lpsnmedia.net *.tvsquared.com *.everestjs.net *.livepe- strict-transport-security
max-age=31536000; includeSubDomains, max-age=31536000; includeSubDomains