enexisgroep.com
HTML metadata
Technology
- CMS
- Gatsby
- Analytics
-
- Google Analytics
- Google Tag Manager
- Fonts
-
- Adobe Fonts
Third-party hosts loaded (5)
- www.googletagmanager.com×2
- api.searchine.net×1
- cdn.searchine.net×1
- use.typekit.net×1
- www.google-analytics.com×1
Social
Registration
- Registrar
- Hosting Concepts B.V. d/b/a Registrar.eu
- Created
- 2016-09-26
- Expires
- 2026-09-26 115 days left
- Updated
- 2025-09-26
- Name servers
-
- dns0.domeinbalie.nl
- dns1.domeinbalie.nl
- dns2.domeinbalie.org
DNS records live
- NS
-
- dns0.domeinbalie.nl
- dns1.domeinbalie.nl
- dns2.domeinbalie.org
- MX
-
- 10 email.domeinbalie.nl
- 10 fallback.domeinbalie.nl
- TXT
-
mandrill_verify.ws1EQLuqpD_p9ocvLxuXzw
Email authentication partial
- SPF
-
v=spf1 include:spf.spamservice.nl mx a include:spf.mandrillapp.com ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=none;policy: none (monitoring only) - DKIM
- no key found at common selectors
Certificate (current)
R13
Expires in 47 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN- permissions-policy
accelerometer=(),ambient-light-sensor=(),battery=(),camera=(),clipboard-read=(),clipboard-write=(),conversion-measurement=(),cross-origin-isolated=(),display-capture=(),encrypted-media=(),execution-while-not-rendered=(),execution-while-out-of-viewport=(),focus-without-user-activation=(),fullscreen=(),gamepad=(),geolocation=(),gyroscope=(),hid=(),idle-detection=(),interest-cohort=(),magnetometer=(),microphone=(),midi=(),navigation-override=(),payment=(),publickey-credentials-get=(),screen-wake-lock=(),serial=(),speaker-selection=(),sync-script=(),sync-xhr=(),trust-token-redemption=(),usb=(),vertical-scroll=(),wake-lock=(),web-share=(),window-placement=(),xr-spatial-tracking=()- x-content-type-options
nosniff- content-security-policy
default-src 'self' 'unsafe-inline' 'unsafe-eval'; connect-src 'self' data: *.google-analytics.com *.cookiebot.com enexisgroep.com *.enexisgroep.com enexisgroep.nl *.enexisgroep.nl enexishuis.nl *.enexishuis.nl *.searchine.net *.youtube.com *.google.com *.google-analytics.com *.googlesyndication.com *.doubleclick.net; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.google-analytics.com *.cookiebot.com *.searchine.net *.cloudflare.com *.googletagmanager.com *.doubleclick.net; img-src 'self' data: *.google-analytics.com *.cookiebot.com enexisgroep.com *.enexisgroep.com enexisgroep.nl *.enexisgroep.nl enexishuis.nl *.enexishuis.nl *.umbraco.com *.google.com *.google.nl *.bitbucket.com *.bing.com *.github.com github.com *.ytimg.com *.doubleclick.net; font-src 'self' *.typekit.net *.gstatic.com; style-src 'self' 'unsafe-inline' 'unsafe-eval' *.searchine.net *.typekit.net *.googleapis.com; frame-src 'self' *.cookiebot.com *.umbraco.com *.google.com *.youtube.com *.doubleclick.net;- strict-transport-security
max-age=31536000; includeSubDomains; preload