carocroc.nl
HTML metadata
Technology
- Server
- nginx
- CMS
- WordPress
- jQuery
- 3.3.1 known XSS (<3.5)
- Ads
-
- Xandr
Third-party hosts loaded (7)
- static.mailplus.nl×19
- m15.mailplus.nl×4
- cdnjs.cloudflare.com×2
- ib.adnxs.com×1
- polyfill.io×1
- secure.adnxs.com×1
- www.google.com×1
Social
Contact
- Phone
Registration
- Registrar
- InterConnect Services B.V.
- Created
- 2009-07-27
- Updated
- 2018-06-14
- Name servers
-
- nsauth1.interconnect-dns.nl
- nsauth2.interconnect-dns.eu
- nsauth3.interconnect-dns.be
DNS records live
- NS
-
- nsauth1.interconnect-dns.nl
- nsauth2.interconnect-dns.eu
- nsauth3.interconnect-dns.be
- MX
-
- 10 carocroc-nl.mail.protection.outlook.com
- Verified for
-
- Microsoft 365
Email authentication partial
- SPF
-
v=spf1 a mx ip4:85.146.201.254 include:spf.signet.nl include:_spf.linqhost.nl include:_spf.mailplus.nl include:spf.protection.outlook.com ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=none; sp=none;policy: none (monitoring only) · sp=none - DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAt1Xwgo4ICud6Tyl4E+EP1Igf8pRfyyZkprVHXSzzznpNvj0x6gYvlIoN/w8/Y/wTyNxnT9SiMjcoVu…
selectors probed - selector1:
Certificate (current)
R12
Expires in 40 days
HTTP security headers
- present
-
- content-security-policy
- findings
-
- missing HSTS
- CSP allows unsafe inline scripts/styles
- missing frame protection
- missing content type protection
- missing Referrer Policy
- missing Permissions Policy
Header values
- content-security-policy
script-src 'self' 'unsafe-inline' 'unsafe-eval' https: https://www.google.com https://www.gstatic.com https://www.recaptcha.net https://tagmanager.google.com https://sc-static.net https://carocroc.nl https://spel.carocroc.nl; script-src-elem 'self' 'unsafe-inline' 'unsafe-eval' https: https://www.google.com https://www.gstatic.com https://www.recaptcha.net https://tagmanager.google.com https://sc-static.net https://carocroc.nl https://spel.carocroc.nl; script-src-attr 'self' 'unsafe-inline' 'unsafe-eval' https: https://www.google.com https://www.gstatic.com https://www.recaptcha.net https://tagmanager.google.com https://sc-static.net https://carocroc.nl https://spel.carocroc.nl, script-src 'self' 'unsafe-inline' 'unsafe-eval' https: https://www.google.com https://www.gstatic.com https://www.recaptcha.net https://tagmanager.google.com https://sc-static.net https://carocroc.nl https://spel.carocroc.nl; script-src-elem 'self' 'unsafe-inline' 'unsafe-eval' https: https://www.google.com htt