centraalbeheer.nl
HTML metadata
Technology
- CMS
- Gatsby
- Stack
- ASP.NET
- Analytics
-
- Google Analytics
- Google Tag Manager
Third-party hosts loaded (5)
- cba.imgix.net×7
- js.monitor.azure.com×1
- tdn.r42tag.com×1
- www.google-analytics.com×1
- www.googletagmanager.com×1
Social
Contact
- Phone
DNS records live
- NS
-
- ns01.brandshelter.com
- ns02.brandshelter.net
- MX
-
- 10 centraalbeheer-nl.mail.protection.outlook.com
- TXT
-
_6kqdy4371thbhe4kujjtc7vkb4vzvogJcckydhk/1GadUZvcToU/2pjW0zRRTsog31gUeBD+3mPcuxu5c7+T5AOo8u58CfFA4gmXhBIDN/LZwV8vE3oBQ==_ds7bmmzxv030yt4ljmsv72xzjyso8ok
- Verified for
-
- Airtable
- Miro
Email authentication strong
- SPF
-
v=spf1 include:spf.mailrelay.achmea.nl ip4:145.219.8.32 ip4:145.219.8.33 ip4:77.222.78.0/28 ip4:87.249.96.110 include:spf.protection.outlook.com include:_spf.zivver.com ip4:46.17.10.160/27 -allstrict (-all) - DMARC
-
v=DMARC1;p=reject;rua=mailto:m6panlfh@ag.eu.dmarcadvisor.compolicy: reject (enforced) - DKIM
-
Show 4 DKIM selectors
- selector1:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAuX9R3FwlLmOQO8t9xAsP+aVTRk1Nt+wSmYcqiyOb8euu4emnGZoRLpXkIzRt1bnsP3hrmkPEAvbM7I… - selector2:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAro5qImrz5ZZamdayXteyeLuvgyG7FVXKCfLr2NWmNvvOgIOA0nz7bUwepnIOW1/yRaCr0/DkwRtSxr… - s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA63Y71MhVqqNhDwhAvpoM5dTgfMnT+rbiVA0hg2+YYukLqsWPnxUXD7woq6g3XVmyQO20qs2wvY5//DC43M… - s2:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA7tzVmiuJJsL+E3FbAWgaLZVqgxPwzWKVF/fy4cLe0ec3ybOR6aKJNxQRt6452nv/8qpLCYUIIbLdQz5V5W…
selectors probed - selector1:
Certificate (current)
DigiCert QuoVadis 2G3 TLS RSA4096 SHA384 2023 CA1
Expires in 201 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- content-security-policy-report-only
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Permissions Policy
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src 'self' *.relay42.com;script-src 'self' 'unsafe-eval' 'unsafe-inline' blob: *.centraalbeheer.nl https://googleads.g.doubleclick.net *.facebook.net https://www.google.com https://pagead2.googlesyndication.com *.linkedin.com *.relay42.com *.r42tag.com *.svtrd.com *.usabilla.com achmeadpm.achmea.nl:9999 ajax.googleapis.com api.usabilla.com app.contentsquare.com bat.bing.com cba.nmrc.nl cdn.ampproject.org cdn.harvest.graindata.com d6tizftlrpuof.cloudfront.net https://*.googletagmanager.com js.monitor.azure.com maps.googleapis.com player.quadia.net r.bing.com snap.licdn.com static.cloud.coveo.com surfly.com t.contentsquare.net tags.nmrc.nl www.dwin1.com https://www.googleadservices.com www.youtube.com www.zenaps.com www.awin1.com https://api-engage-eu.sitecorecloud.io https://d35vb5cccm4xzp.cloudfront.net https://d1mj578wat5n4o.cloudfront.net *.mypurecloud.ie https://acc.cdn.dgv.aov.achmea.nl https://cdn.dgv.aov.achmea.nl;style-src 'self' 'unsafe-inline' d6tizftlrpuof.cloudfront.- strict-transport-security
max-age=31536000; includeSubDomains- content-security-policy-report-only
default-src 'self' *.relay42.com;script-src 'self' 'unsafe-eval' 'unsafe-inline' blob: *.centraalbeheer.nl https://googleads.g.doubleclick.net *.facebook.net https://www.google.com https://pagead2.googlesyndication.com *.linkedin.com *.relay42.com *.r42tag.com *.svtrd.com *.usabilla.com achmeadpm.achmea.nl:9999 ajax.googleapis.com api.usabilla.com app.contentsquare.com bat.bing.com cba.nmrc.nl cdn.ampproject.org cdn.harvest.graindata.com d6tizftlrpuof.cloudfront.net https://*.googletagmanager.com js.monitor.azure.com maps.googleapis.com player.quadia.net r.bing.com snap.licdn.com static.cloud.coveo.com surfly.com t.contentsquare.net tags.nmrc.nl www.dwin1.com https://www.googleadservices.com www.youtube.com www.zenaps.com www.awin1.com https://api-engage-eu.sitecorecloud.io https://d35vb5cccm4xzp.cloudfront.net https://d1mj578wat5n4o.cloudfront.net *.mypurecloud.ie https://acc.cdn.dgv.aov.achmea.nl https://cdn.dgv.aov.achmea.nl;style-src 'self' 'unsafe-inline' d6tizftlrpuof.cloudfront.