energids.be
HTML metadata
Technology
- Server
- Apache
Third-party hosts loaded (2)
- www.energuide.be×2
- cdn-cookieyes.com×1
Social
DNS records live
- NS
-
- ns3.inventis.be
- ns4.inventis.be
- MX
-
- 10 mx2.hc2200-92.eu.iphmx.com
- 10 virtualmail.webpower.eu
- 60 mx1.hc2200-92.eu.iphmx.com
- Verified for
-
- Microsoft 365
Email authentication weak
- SPF
-
v=spf1 exists:%{i}.spf.hc2200-92.eu.iphmx.com -allstrict (-all) · multiple SPF records - DMARC
- not published
- DKIM
- no key found at common selectors
Certificate (current)
E7
Expires in 86 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN- permissions-policy
accelerometer=(self "https://www.youtube.com" "https://www.tiktok.com"), autoplay=(self "https://www.youtube.com" "https://www.tiktok.com" "https://w.soundcloud.com"), camera=(), display-capture=(), encrypted-media=(self "https://www.youtube.com" "https://www.tiktok.com"), fullscreen=(self "https://www.youtube.com" "https://www.tiktok.com" "https://w.soundcloud.com"), geolocation=(), gyroscope=(self "https://www.youtube.com" "https://www.tiktok.com"), magnetometer=(), microphone=(), midi=(), payment=(), picture-in-picture=(self "https://www.youtube.com" "https://www.tiktok.com"), publickey-credentials-get=(self "https://challenges.cloudflare.com"), usb=(), web-share=(self "https://www.youtube.com" "https://www.tiktok.com"), xr-spatial-tracking=()- x-content-type-options
nosniff- content-security-policy
default-src 'self' https://*.energids.site https://energids.site https://*.energids.be https://energids.be https://www.energids.be https://*.enerkids.site https://enerkids.site https://*.enerkids.be https://enerkids.be https://www.enerkids.be https://*.energuide.site https://energuide.site https://*.energuide.be https://energuide.be https://www.energuide.be https://*.ddev.site http://*.ddev.site http://localhost:* https://localhost:* http://127.0.0.1:* https://127.0.0.1:*; script-src 'self' 'unsafe-inline' https://*.energids.site https://energids.site https://*.energids.be https://energids.be https://www.energids.be https://*.enerkids.site https://enerkids.site https://*.enerkids.be https://enerkids.be https://www.enerkids.be https://*.energuide.site https://energuide.site https://*.energuide.be https://energuide.be https://www.energuide.be https://*.ddev.site http://*.ddev.site http://localhost:* https://localhost:* https://cdn-cookieyes.com https://www.googletagmanager.com https://ww- strict-transport-security
max-age=31536000; includeSubDomains