bmn.nl

.nl crawl

First seen 2026-05-23 · Last seen 2026-05-30 · ok HTTP/1.1 200 2332 ms crawled 2026-05-29

US · 104.16.121.107 · AS13335 Cloudflare, Inc.

Reputation 94/100 dmarc monitor-only

Classifying

HTML metadata

Language
nl-NL

Technology

CDN
Cloudflare
Analytics
  • Cloudflare Insights

Third-party hosts loaded (2)

  • client-version.cf.emarsys.net×1
  • static.cloudflareinsights.com×1

Registration

Registrar
NameWeb
Created
2009-02-18
Updated
2023-08-10
Name servers
  • ns1-06.azure-dns.com
  • ns3-06.azure-dns.org
  • ns2-06.azure-dns.net
  • ns4-06.azure-dns.info

DNS records live

NS
  • ns1-06.azure-dns.com
  • ns2-06.azure-dns.net
  • ns3-06.azure-dns.org
  • ns4-06.azure-dns.info
MX
  • 10 bmn-nl.mail.protection.outlook.com
TXT
  • knowbe4-site-verification=fd84db026d16134f09933e18286ce91a
Verified for
  • Anthropic
  • Apple
  • Atlassian
  • GlobalSign
  • Google
  • Microsoft 365

Email authentication partial

SPF
v=spf1 ip4:213.136.9.80/28 ip4:159.183.209.237 ip4:212.3.230.164 ip4:213.244.142.227 ip4:178.162.177.129 ip4:148.105.8.0/21 ip4:46.31.48.0/21 ip4:159.183.209.237 include:spf.bmaccess.eu include:spf.protection.outlook.com include:spf.mandrillapp.com include:lms.plusport.com include:spf.ecmanage.nl include:spf.crowdtech.com ip4:4.245.77.0/28 include:spf.mailjet.com ~all
softfail (~all)
DMARC
v=DMARC1; p=none; sp=none; rua=mailto:415ea7d4@in.mailhardener.com; ruf=mailto:415ea7d4@in.mailhardener.com
policy: none (monitoring only) · sp=none
DKIM
  • selector1: v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAvHAxkI31haXyH6/wNvxKkTELYFOtNhBmi6O9O4oypwUvgL8iTO+Ogi1KuNDDc7uOtZ2uZFsAYp0djz…
selectors probed

Certificate (current)

Sectigo Public Server Authentication CA OV R36
from 2026-02-25 to 2027-02-26
Expires in 270 days

HTTP security headers

Header hygiene 85/100 Checked live page: https://www.bmn.nl/

present
  • strict-transport-security
  • content-security-policy
  • x-frame-options
  • x-content-type-options
  • referrer-policy
findings
  • CSP uses wildcard sources
  • weak frame protection
  • missing Permissions Policy
Header values
referrer-policy
strict-origin-when-cross-origin
x-frame-options
SAMEORIGIN, SAMEORIGIN
x-content-type-options
nosniff
content-security-policy
script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com commerce-payments-sdk.adobe.io www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://*.gstatic.com https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com *.bmn.nl *.hotjar.com *.cookiebot.
strict-transport-security
max-age=31536000; includeSubDomains; preload

Links to (1)

Linked from (4)