f1re.nl

.nl crawl

First seen 2026-05-11 · Last seen 2026-05-16 · ok HTTP/1.1 200 3219 ms crawled 2026-05-16

DE · 49.13.55.1 · AS24940 Hetzner Online GmbH

Reputation 92/100 no dmarc policy

Classifying

HTML metadata

Title
Home | F1RE
Language
en
Canonical
https://www.f1re.nl/
Translations
  • en

Open Graph

url
https://www.f1re.nl/
title
Home | F1RE

Technology

Server
nginx
Analytics
  • Google Tag Manager

Third-party hosts loaded (4)

  • www.googletagmanager.com×3
  • maps.googleapis.com×1
  • unpkg.com×1
  • www.google.com×1

Social

Contact

Email
Phone
Address
Plaza ArenaGebouw: DaliHerikerbergweg 27011

Registration

Registrar
The Registrar Company B.V.
Created
2020-10-05
Updated
2021-11-30
Name servers
  • ns1.thednscompany.com
  • ns2.thednscompany.com
  • ns3.thednscompany.com

DNS records live

NS
  • ns1.thednscompany.com
  • ns2.thednscompany.com
  • ns3.thednscompany.com
MX
  • 10 smtp.otys.nl
Verified for
  • Microsoft 365

Email authentication weak

SPF
v=spf1 include:_spf.f1re.nl include:_spf.infinitesources.nl include:spf.protection.outlook.com include:broadbean.net ~all
softfail (~all)
DMARC
not published
DKIM
no key found at common selectors

Certificate (current)

Sectigo Public Server Authentication CA DV R36
from 2025-09-29 to 2026-09-30
Expires in 132 days

HTTP security headers

Header hygiene 85/100 Checked live page: https://www.f1re.nl/

present
  • strict-transport-security
  • content-security-policy
  • x-frame-options
  • x-content-type-options
  • referrer-policy
findings
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
  • missing Permissions Policy
Header values
referrer-policy
strict-origin-when-cross-origin
x-frame-options
SAMEORIGIN
x-content-type-options
nosniff
content-security-policy
base-uri 'self'; default-src 'self'; media-src * data: blob: 'self'; script-src 'nonce-1KyisOTPOW3C8X5NcyXvsQ==' 'sha256-0A4eUiOTjkpObIX3KW6OPLr8U3fzEavcWcIIeLaSyIE=' 'unsafe-eval' 'strict-dynamic'; connect-src * data: blob: 'unsafe-inline'; img-src * data: blob: 'unsafe-inline'; frame-src * data: blob:; style-src * data: blob: 'unsafe-inline'; font-src * data: blob: 'unsafe-inline'; object-src 'none';
strict-transport-security
max-age=31536000; includeSubDomains; preload

Links to (4)

Linked from (1)