dhm.nl

.nl crawl

First seen 2026-06-03 · Last seen 2026-06-04 · ok HTTP/1.1 200 979 ms crawled 2026-06-03

IE · 52.51.110.71 · AS16509 Amazon.com, Inc.

Reputation 92/100 no dmarc policy

Classifying

HTML metadata

Title
DHM | Beveiligen van beleid tot en met uitvoering inclusief kwaliteitsborging
Description
DHM is de facto, de standaard voor security management in Nederland

Technology

Server
Welcome
jQuery
1.9.0 known XSS (<3.5)
Stack
ASP.NET

Third-party hosts loaded (6)

  • s3.eu-west-1.amazonaws.com×23
  • apollobusiness.freetls.fastly.net×6
  • apollobusiness.global.ssl.fastly.net×1
  • d258m94yw7900v.cloudfront.net×1
  • maxcdn.bootstrapcdn.com×1
  • wurfl.io×1

Contact

Email
Phone
Address
SOBA Security Academy BVRijnzathe 83454 PV De MeernTelefoon: 030 - 666 777 3Mail:info@dhm.nlBTW nummer: NL82051796B01KVK nummer: 56626770

DNS records live

NS
  • ns-h.dns.yourhosting.eu
  • ns-i.dns.yourhosting.nu
  • ns-j.dns.yourhosting.nl
MX
  • 10 mx2.mtaroutes.com
  • 15 mx3.mtaroutes.com
  • 20 mx4.mtaroutes.com
  • 5 mx1.mtaroutes.com
TXT
  • 52.51.110.71

Email authentication weak

SPF
v=spf1 include:spf.protection.outlook.com include:spf.eu.signature365.net include:amazonses.com -all
strict (-all)
DMARC
not published
DKIM
no key found at common selectors

Certificate (current)

R13
from 2026-04-19 to 2026-07-18
Expires in 44 days

HTTP security headers

Header hygiene 70/100 Checked live page: https://www.dhm.nl/

present
  • strict-transport-security
  • content-security-policy
  • x-frame-options
  • permissions-policy
findings
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
  • weak frame protection
  • missing content type protection
  • missing Referrer Policy
Header values
x-frame-options
AllowAll
permissions-policy
accelerometer=(), camera=(), geolocation=(), gyroscope=(), magnetometer=(), microphone=(), payment=(), usb=()
content-security-policy
default-src *; style-src * 'unsafe-inline'; script-src * 'unsafe-inline' 'unsafe-eval'; font-src * 'unsafe-inline' 'unsafe-eval' data:; img-src * data: 'unsafe-inline'; connect-src * 'unsafe-inline'; frame-src *;
strict-transport-security
max-age=31536000

Links to (4)

Linked from (2)