deroma.be

.be crawl

First seen 2026-05-27 · Last seen 2026-05-30 · ok HTTP/1.1 200 918 ms crawled 2026-05-30

BE · 195.225.164.3 · AS59943 Level 27 BVBA

Reputation 92/100 weak subdomain policy

Classifying

HTML metadata

Title
Home | De Roma
Language
en
Canonical
https://www.deroma.be/en/
Translations
  • en
  • fr
  • nl

Open Graph

title
Home

Technology

Analytics
  • Google Tag Manager

Third-party hosts loaded (1)

  • www.googletagmanager.com×1

Social

Contact

Address
De RomaTurnhoutsebaan 2862140 Borgerhoutshow route

DNS records live

NS
  • ns.nscluster.eu
  • ns.nscluster.hk
  • ns.nscluster.lv
  • ns.nscluster.uk
  • ns.nscluster.us
MX
  • 0 deroma-be.mail.protection.outlook.com
TXT
  • x7KSLLpf4hHvdQKBXEvekhJtIC8IRrRf
Verified for
  • Brevo
  • Google
  • Meta
  • Microsoft 365

Email authentication strong

SPF
v=spf1 include:spf.mandrillapp.com include:spf.protection.outlook.com include:servers.mcsv.net include:spf.sendinblue.com mx include:amazonses.com -all
strict (-all)
DMARC
v=DMARC1; p=reject; sp=none; pct=100; ri=86400; rua=mailto:rua@dmarc.brevo.com
policy: reject (enforced) · sp=none
DKIM
Show 4 DKIM selectors
  • selector1: v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDkZjHv9SMir8ADXTSZvAicCUz1+4sjoTnPIymVVKG1SXALW8b9HuHJVlDpNHGq8roUlxr3l62zY75FotxII2…
  • selector2: v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCisKL0QCyzLmbDdRy/dNqWQAuKmwfx4n8FbofmRgu+l8MdY4mI2Yg6djYfb60R+c0noX5GDmJiYNvkhIS2bg…
  • k1: k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDbNrX2cY/GUKIFx2G/1I00ftdAj713WP9AQ1xir85i89sA2guU0ta4UX1Xzm06XIU6iBP41VwmPwBGRNofhBVR+e6WHUo…
  • mail: k=rsa;p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDeMVIzrCa3T14JsNY0IRv5/2V1/v2itlviLQBwXsa7shBD6TrBkswsFUToPyMRWC9tbR/5ey0nRBH0ZVxp+lsmTxid2Y2z…
selectors probed

Certificate (current)

R13
from 2026-04-24 to 2026-07-23
Expires in 53 days

HTTP security headers

Header hygiene 80/100 Checked live page: https://www.deroma.be/en/

present
  • strict-transport-security
  • content-security-policy
  • x-frame-options
  • x-content-type-options
  • referrer-policy
findings
  • short HSTS max-age
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
  • missing Permissions Policy
Header values
referrer-policy
no-referrer, strict-origin-when-cross-origin
x-frame-options
DENY
x-content-type-options
nosniff
content-security-policy
default-src 'self' https://*.youtube.com https://*.youtu.be https://*.vimeo.com https://*.spotify.com https://*.soundcloud.com https://*.instagram.com https://*.tiktok.com https://forms.office.com https://*.google-analytics.com https://*.analytics.google.com https://*.google.com https://*.googletagmanager.com https://*.googlesyndication.com https://analytics.tiktok.com https://*.doubleclick.net https://widget.tablefever.com https://www.facebook.com https://fonts.gstatic.com; block-all-mixed-content; img-src data: 'self' https://placeholder.inventis.be https://*.ytimg.com https://*.youtube.com https://*.vimeocdn.com https://*.google-analytics.com https://*.googletagmanager.com https://fonts.gstatic.com https://www.facebook.com https://*.google.be https://*.google.nl https://*.googlesyndication.com; object-src 'none'; script-src 'self' 'strict-dynamic' 'unsafe-inline' 'unsafe-eval' https://*.googletagmanager.com 'nonce-AsVsSVPU5l4n2oqXdRnHIA=='; style-src 'self' 'unsafe-inline' https://*
strict-transport-security
max-age=2592000, max-age=63072000;includeSubDomains

Links to (21)

Linked from (1)