dutch-headshop.eu
HTML metadata
Technology
- Server
- nginx
- CMS
- Gatsby
- Fonts
-
- Adobe Fonts
Third-party hosts loaded (6)
- use.typekit.net×1
- www.dutch-headshop.at×1
- www.dutch-headshop.be×1
- www.dutch-headshop.de×1
- www.dutch-headshop.fr×1
- www.dutch-headshop.nl×1
Contact
DNS records live
- NS
-
- ns1.digistate.eu
- ns2.digistate.nl
- ns3.digistate.org
- MX
-
- 10 mail.dutch-headshop.eu
- 20 mail2.dutch-headshop.eu
- TXT
-
8949bfc1174k43qj085043q5s20rly67_0l6rp3ns89q43mnz6g9b8ahlobhiraa_ob8yxafcsv8jl9dzwqb7k3lhff0x8xh
- Verified for
-
Email authentication strong
- SPF
-
v=spf1 a mx ip4:193.27.86.150 ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=quarantine; sp=none; rua=mailto:abuse@dutch-headshop.eupolicy: quarantine · sp=none - DKIM
- no key found at common selectors
Certificate (current)
Trust Provider B.V. TLS RSA CA G1
Expires in 270 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com maxcdn.bootstrapcdn.com https://fonts.bunny.net *.alothemes.com *.magepow.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.paypal.com *.vivapayments.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.awin1.com *.zenaps.com td.doubleclick.net *.googletagmanager.com app.youshouldask.ai *.sendcloud.sc *.jsdelivr.net 'self' 'unsafe-inline'- strict-transport-security
max-age=31536000