cafelaken.nl

.nl crawl

First seen 2026-05-31 · Last seen 2026-05-31 · ok HTTP/1.1 200 581 ms crawled 2026-06-01

NL · 213.207.97.37 · AS9150 ML Consultancy

Reputation 94/100 dmarc monitor-only

Classifying

HTML metadata

Title
Home - Café Laken
Description
Welkom in Café Laken, het nieuwe café van Museum de Lakenhal te Leiden. We serveren herkenbare gerechten voor lunch en tussendoor, waarbij we samenwerken met lokale leveranciers.
Language
nl

Technology

Server
nginx
Fonts
  • Adobe Fonts

Third-party hosts loaded (1)

  • use.typekit.net×1

DNS records live

NS
  • ns0.transip.net
  • ns1.transip.nl
  • ns2.transip.eu
MX
  • 0 cafelaken-nl.mail.protection.outlook.com
Verified for
  • Microsoft 365

Email authentication partial

SPF
v=spf1 include:spf.protection.outlook.com -all
strict (-all)
DMARC
v=DMARC1; p=none;
policy: none (monitoring only)
DKIM
  • selector1: v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAt0Bf1DgdXuCsYJMraKRVuRaaZUzpeb8h13WctooczIdMlkbjgDvuEt2ju/91fDmAhzx3auohY8m9Zp…
  • selector2: v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAvz1tGhz048yFZoJ8ENQBfMjyLGHCkUno02acQyls4IQuSrIlA72YyWhYTO2PIatVXWKGI0zCoy4iNR…
selectors probed

Certificate (current)

R13
from 2026-05-22 to 2026-08-20
Expires in 77 days

HTTP security headers

Header hygiene 85/100 Checked live page: https://cafelaken.nl/

present
  • strict-transport-security
  • content-security-policy
  • x-frame-options
  • x-content-type-options
  • referrer-policy
findings
  • CSP allows unsafe inline scripts/styles
  • weak content type protection
  • missing Permissions Policy
Header values
referrer-policy
strict-origin-when-cross-origin
x-frame-options
SAMEORIGIN
x-content-type-options
nosniff, nosniff
content-security-policy
default-src 'self' https:; font-src 'self' https: http: data:; img-src 'self' https: http: data: 'unsafe-inline'; object-src 'none'; script-src 'self' https: 'unsafe-inline' 'unsafe-eval'; style-src 'self' https: 'unsafe-inline' 'unsafe-eval'; frame-ancestors 'self'; connect-src 'self' ws: wss: https: http://localhost:3035 ws://localhost:3035 ws://dev.lico.nl:3035
strict-transport-security
max-age=63072000; includeSubDomains, max-age=63072000; preload

Links to (2)

Linked from (1)