eyecare.nl
HTML metadata
Technology
- CDN
- Azure Front Door
- CMS
- Next.js
- JS framework
- Next.js
- Analytics
-
- Google Tag Manager
Third-party hosts loaded (2)
- cdn.builder.io×59
- www.googletagmanager.com×1
Social
Registration
- Registrar
- Hostnet B.V.
- Created
- 2000-02-16
- Updated
- 2025-06-18
- Name servers
-
- ns02.hostnet.nl
- ns01.hostnet.nl
DNS records live
- NS
-
- ns01.hostnet.nl
- ns02.hostnet.nl
- MX
-
- 0 d337557.a.ess.de.barracudanetworks.com
- 5 d337557.b.ess.de.barracudanetworks.com
- Verified for
-
Email authentication partial
- SPF
-
v=spf1 a:mailrelay.open-ict.nl a:vps.hvdz.nl include:spf.turbo-smtp.com include:_spf.mailer.twinfield.com include:spf.flowmailer.net include:spf.protection.outlook.com include:mailplus.nl include:_spf.hostnet.nl include:spf.ess.de.barracudanetworks.com include:spf.acuitas3.com ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=nonepolicy: none (monitoring only) - DKIM
-
- google:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAkqyffxqSXZFfZqZXzYWbHRQz8qtVEhypcMcalC2tbVHWSUGBfOE1clNEXJENXcenRRhgr5Zvyed+Ew…
selectors probed - google:
Certificate (current)
R12
Expires in 62 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Permissions Policy
Header values
- referrer-policy
origin-when-cross-origin- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src 'self' *.ocuco.com *.oh.ocuco.com cdn.builder.io;script-src 'self' 'unsafe-eval' 'unsafe-inline' payments.worldpay.com www.datadoghq-browser-agent.com *.googletagmanager.com maps.googleapis.com *.googleadservices.com *.googlesyndication.com *.facebook.com *.facebook.net *.bing.com *.jdt8.net *.doubleclick.net *.clarity.ms *.hotjar.com *.fittingbox.com cdn.jsdelivr.net consent.cookiebot.eu consent.cookiebot.com consentcdn.cookiebot.com *.klaviyo.com cdnjs.cloudflare.com load.power.eyecare.nl;font-src 'self' data: fonts.gstatic.com fonts.googleapis.com *.ocuco.com *.oh.ocuco.com ohdevstorage.blob.core.windows.net *.klaviyo.com;img-src 'self' data: blob: cdn.builder.io *.ocuco.com *.oh.ocuco.com *.acuitas3.com ohcxassets-g2exgwd2csbjc3gx.z01.azurefd.net *.gstatic.com *.googleadservices.com google.com *.google.com *.google.com.pk *.google.ie *.googlesyndication.com *.googletagmanager.com *.googleapis.com *.doubleclick.net *.facebook.com *.facebook.net *.bing.com *.jdt8.net jdt8- strict-transport-security
max-age=63072000; includeSubDomains; preload