breemes.be
HTML metadata
Technology
- CDN
- Amazon CloudFront
- Server
- *
- jQuery
- 3.2.1 known XSS (<3.5)
- Stack
- Java
- Analytics
-
- Google Tag Manager
- Fonts
-
- Google Fonts
Third-party hosts loaded (5)
- d36wi5vgvc34gm.cloudfront.net×24
- cdnjs.cloudflare.com×3
- cdn.jsdelivr.net×1
- fonts.googleapis.com×1
- www.googletagmanager.com×1
DNS records live
- NS
-
- ns0.transip.net
- ns1.transip.nl
- ns2.transip.eu
- MX
-
- 5 breemes-be.mail.protection.outlook.com
- Verified for
-
- Microsoft 365
Email authentication weak
- SPF
-
v=spf1 mx ip4:195.243.225.91 ip4:5.102.138.187 ip4:5.102.138.137 include:spf.protection.outlook.com include:amazonses.com include:eu-west-1.amazonses.com ~allsoftfail (~all) - DMARC
- not published
- DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA4IS0mUW4bO56rMqq1WRphJa7OVNR0Ulg5eSA8lPfKp5QCROJ0VG1xT2R8igGahcl+r4aCEl1wCgJZf… - selector2:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA3wVOo9I+dZKD/eTZuoIzJfczitQkugntOo5CEISUB5JoJAWxBxDt+LlGpukvYci+iFuQsz0ydiPD+G…
selectors probed - selector1:
Certificate (current)
Sectigo Public Server Authentication CA DV R36
Expires in 181 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-content-type-options
- findings
-
- CSP uses wildcard sources
- missing frame protection
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-content-type-options
nosniff- content-security-policy
frame-ancestors 'self' https://service.ariba.com https://s1.ariba.com https://s1-s2.ariba.com https://s2.ariba.com https://s1-2-eu.ariba.com https://s1-2.ariba.com https://dsrmcs01.apollotyres.com https://qsrmcs01.apollotyres.com https://psrmcs01.apollotyres.com https://qsrmcs01.apollotyres.com:50001 https://dsrmcs01.apollotyres.com:50001 https://psrmcs01.apollotyres.com:50001 https://s1-eu.ariba.com https://stgadmin.itsmehosting.com https://istem.itsmehosting.com https://service-2.ariba.com https://srm7.linde.grp https://int-srm.america.apci.com:9080 https://eudemo5.corcentricplatform.com https://punchoutcommerce.com https://ebusiness-qas.sabic.com https:supplierselfservices-qas.sabic.com https://juhdq09.sabic.com:1443/* https://juhdq09.sabic.com https://juhdq09.sabic.com:1443/* https://juhdq09.sabic.com:1443/ https://erp-qas.sabic.com https://erp.sabic.com https://ebusiness.sabic.com https://supplierselfservices.sabic.com https://p09aas00.sabic.com:1443/* https://p09aas01.sabic.c- strict-transport-security
max-age=31536000 ; includeSubDomains