expresswear.nl
HTML metadata
Technology
- Server
- Apache
- jQuery
- 2.2.4 known XSS (<3.5)
- Analytics
-
- Google Tag Manager
- Fonts
-
- Google Fonts
Third-party hosts loaded (9)
- fonts.googleapis.com×2
- ajax.googleapis.com×1
- cdn-4.convertexperiments.com×1
- fonts.gstatic.com×1
- selfservice.robinhq.com×1
- snapppt.com×1
- widget.prod.faslet.net×1
- www.feedbackcompany.com×1
- www.googletagmanager.com×1
Social
Contact
- Phone
DNS records live
- NS
-
- ns1.sqr.nl
- ns2.sqr.domains
- ns3.sqr.cloud
- MX
-
- 10 mx1.antispam-login.net
- 20 mx2.antispam-login.net
- TXT
-
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAw0fI+78skWDxynTNKTZh dr7ypsdANdMn6le03afCflNNWKU9VTKOXF2tb5bgPVgpCAXnQNheWqMWpJNYPJce Eq+JTFXOzWZra130zm3xdNncIHmjWnxsX6BnSPmEQfEH9EG3qWWKGzsFtM87UL0f TGGcRygO4Xf4qcYOxYIUDAddqPgRgjUKxlfpP6S38PrmueMIEctmlf9ndJZbt6Xx 18CZ7djtssbKRe/h5ddKa98yAMchwA1TSCBYzO3GSrqEtgT04OwltP9V4oub+kUl VNaMblSYW3yqmoApW8x5EZAw1KyD1SiKKnUDQ2qN+03shUyJro4SS563Pj9b+/5j FwIDAQABMS=8E50D24E4007F20A8C90F2D6E5FB14375FD43ADD
Email authentication weak
- SPF
-
v=spf1 a mx a:expresswear-web1.svr.previder.nl ip4:94.124.142.235 include:_spf.mailplus.nl include:spf.cyso.nl ip4:62.165.80.75 ip4:62.179.121.36 ip4:194.187.76.151 include:_spf.supportbyrobin.com ~allsoftfail (~all) - DMARC
- not published
- DKIM
-
- s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEArQ9Pw80Ea4tGx/9KgFomiCjFx5ChLtfNwa19IG/CQ6tmSCxmWkIK59P/kpCXVhMN7jgdNLtNMK6VTuugtj… - s2:
k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQD6wgeC8JulsznECnjEptI7+FVTNdnelCnsghlLkpSfla8q9YHRV0d+BiAyESMMMUJLJRjbwOIm7MYcEipLNd1/r7…
selectors probed - s1:
Certificate (current)
Sectigo Public Server Authentication CA OV R36
Expires in 264 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- cross-origin-opener-policy
- cross-origin-embedder-policy
- cross-origin-resource-policy
- findings
-
- short HSTS max-age
- CSP uses wildcard sources
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN- permissions-policy
geolocation=(self), payment=(self)- x-content-type-options
nosniff- content-security-policy
frame-ancestors 'self'; frame-src 'self' youtube.com *.youtube.com *.pinterest.com *.facebook.com *.robinhq.com *.sleeknote.com *.google.com *.gstatic.com *.googleanalytics.com *.google-analytics.com *.googletagmanager.com *.googleapis.com;- strict-transport-security
max-age=5; includeSubDomains- cross-origin-opener-policy
same-origin-allow-popups- cross-origin-embedder-policy
unsafe-none- cross-origin-resource-policy
strict-origin-when-cross-origin
Links to (7)
Linked from (1)
Use this data via API
Everything on this page for expresswear.nl is available as JSON from the indexo.dev REST & MCP API.
curl "https://indexo.dev/api/v1/domains/expresswear.nl" \ -H "X-API-Key: idx_..."