denengelsen.eu
HTML metadata
Technology
- Server
- nginx
- Analytics
-
- Google Tag Manager
- Fonts
-
- Google Fonts
Third-party hosts loaded (4)
- fonts.googleapis.com×3
- fonts.gstatic.com×1
- werkenbijdenengelsen.eu×1
- www.googletagmanager.com×1
Social
Contact
- Phone
DNS records live
- NS
-
- ns0.nl
- ns11.net
- ns5.be
- MX
-
- 0 denengelsen-eu.mail.protection.outlook.com
- 10 mx.ns0.email
- TXT
-
Show 4 TXT records
mandrill_verify._0I-8RPEBPBYKzoq-OeVEwsending_domain1026523=57de1639834733c0b02089ca3b0db39ac136a2690a072d86c1baa739dccb4059duo_sso_verification=Y1so4nk1xYDqpRNrzknZ8cAsCnwsFvXODOZvSv7Wzz5GLn8dEeIHNrJPwjyvlCJGpardot1026523=bd3ee3467674a21b74d6e9ed5b9e0fc92cef74731de4d9543ab08bd8dce4a9ed
- Verified for
-
- Microsoft 365
Email authentication partial
- SPF
-
v=spf1 ip4:54.240.107.243 ip4:54.240.107.244 ip4:130.117.72.19 ip4:147.161.172.249 include:spf.protection.outlook.com exists:%{i}._spf.mta.salesforce.com include:o365.crossware.co.nz include:spf.mandrillapp.com include:et._spf.pardot.com include:spf-a.authsmtp.com include:spf-b.authsmtp.com include:_spfautoline.ponautomotive.com include:spf.flowmailer.net ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=none; rua=mailto:dmarc@smtpeter.com,mailto:dmarc@inbound.flowmailer.net; ruf=mailto:DMARC@denengelsen.eu,mailto:dmarc@inbound.flowmailer.net; sp=none; fo=0; ri=86400policy: none (monitoring only) · sp=none - DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAzmQaKy3RYNt9cpncMAlFoTQteGcyv2h/dHAUR8HQbT4prbw2g3lLrDRtN/uu6abULNeiMzb5qVJze/… - selector2:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA/7QxDnoHuHB3LQivtT3ufocI6PHWrtuyw0oRXtrN/oVVv+LVWbNbhQKr5v3IOEkesfyvX6jjFwtSm6… - k2:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAv2aC2KjGKLOwTweBY5A9RpjsxaBXR9r7OAU6U8/zn92ivImI75naUujWbItRI/QmL1jy5PWGqLwoUA…
selectors probed - selector1:
Certificate (current)
Sectigo Public Server Authentication CA DV R36
Expires in 69 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Permissions Policy
Header values
- referrer-policy
same-origin- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src 'self'; connect-src *; font-src * data:;img-src * data:; script-src * 'unsafe-inline' 'unsafe-eval'; style-src * 'unsafe-inline'; frame-ancestors werkenbijdenengelsen.eu www.werkenbijdenengelsen.eu denengelsen.eu www.denengelsen.eu; frame-src *- strict-transport-security
max-age=31536000; includeSubdomains