buckaroo.be
HTML metadata
Technology
- Analytics
-
- Google Tag Manager
- Social widgets
-
- YouTube Embed
Third-party hosts loaded (7)
- www.buckaroo.eu×3
- i.ytimg.com×1
- js-eu1.hsforms.net×1
- widget.kapa.ai×1
- www.buckaroo.nl×1
- www.googletagmanager.com×1
- www.youtube.com×1
Social
Contact
- Phone
DNS records live
- NS
-
- ns0.transip.net
- ns1.transip.nl
- ns2.transip.eu
- MX
-
- 0 buckaroo-be.mail.protection.outlook.com
- TXT
-
buckaroo-site-north.azurewebsites.net.
- Verified for
-
- Atlassian
Email authentication weak
- SPF
-
v=spf1 ip4:188.203.200.65/27 ip4:137.116.199.163/32 ip4:195.177.214.0/23 include:spf.flowmailer.net include:spf.by-tres.nl include:spf.protection.outlook.com include:_spf.salesforce.com a mx -allstrict (-all) - DMARC
- not published
- DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEApQAUlf4wR3BO8vXdne4AA8mVFBEVSfWBdIcVRJVSV5xVo5QErctYe0x1B0dMX8ELdo8KdI/xrmVbGy… - selector2:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA1n3UP/LZIy94J3JMNvF9cCH9pZRQhSGaGiHSyEpyeQK9deNv2iLR/fImo/AsaOLKjATjUob7qJvWbY…
selectors probed - selector1:
Certificate (current)
R12
Expires in 31 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- weak frame protection
- weak content type protection
Header values
- referrer-policy
no-referrer, origin-when-cross-origin- x-frame-options
SAMEORIGIN, SAMEORIGIN- permissions-policy
accelerometer=(), camera=(), geolocation=(), gyroscope=(), magnetometer=(), microphone=(), payment=(), usb=(), accelerometer=(), camera=(), geolocation=(), gyroscope=(), magnetometer=(), microphone=(), payment=(), usb=()- x-content-type-options
nosniff, nosniff- content-security-policy
script-src-elem *.amazonaws.com *.clarity.ms *.google.com *.googleadservices.com *.hubspotusercontent-eu1.net *.kapa.ai *.recaptcha.net *.visitorqueue.com https://*.cookiebot.com/ https://*.cookiebot.eu https://*.doubleclick.net/ https://*.formstack.io/ https://*.hotjar.com/ https://*.hsadspixel.net/ https://*.hs-analytics.net/ https://*.hs-banner.com/ https://*.hscta.net/ https://*.hsforms.net/ https://*.hs-scripts.com/ https://*.hubspot.com/ https://*.leadinfo.net/ https://*.marketingautomation.services/ https://*.usemessages.com/ https://connect.facebook.net/ https://recaptcha.net/ https://snap.licdn.com https://static.hsappstatic.net https://unpkg.com https://www.google-analytics.com/ https://www.googletagmanager.com/ https://www.gstatic.com/ 'self' 'unsafe-inline';script-src *.amazonaws.com *.buckaroo.io *.google.com *.hubspotusercontent-eu1.net *.recaptcha.net *.visitorqueue.com https://*.cookiebot.com/ https://*.doubleclick.net/ https://*.formstack.io/ https://*.hsadspixel.net/- strict-transport-security
max-age=31536000
Links to (9)
- youtube.com×1
- wallonie.be×1
- twitter.com×1
- linkedin.com×1
- google.com×1
- github.com×1
- facebook.com×1
- buckaroo.nl×1
- buckaroo.io×1