facilicomfoundation-samenvoorelkaar.nl

.nl crawl

First seen 2026-06-04 · Last seen 2026-06-04 · ok HTTP/1.1 200 1674 ms crawled 2026-06-04

US · 104.21.35.167 · AS13335 Cloudflare, Inc.

Reputation 100/100

Classifying

HTML metadata

Title
365 platform
Description
Hier vind je al het vrijwilligerswerk, doing good challenges én vrijwilligers in jouw buurt verzameld.
Language
nl

Open Graph

ttl
1705251
url
https://www.facilicomfoundation-samenvoorelkaar.nl/
title
homepage facilicom 365 impact platform
locale
nl_NL
site name
365 platform

Technology

CDN
Cloudflare
Analytics
  • Google Tag Manager

Third-party hosts loaded (2)

  • cdn.onesignal.com×1
  • www.googletagmanager.com×1

DNS records live

NS
  • kellen.ns.cloudflare.com
  • nataly.ns.cloudflare.com
TXT
  • mandrill_verify.Hic-8QI9FCDoeotuVSmSqQ
  • mandrill_verify.UjIU3HU8RCdqdwGv71OHZQ

Email authentication no MX

SPF
v=spf1 a mx include:_spf.hostnet.nl -all
strict (-all) · multiple SPF records
DMARC
v=DMARC1; p=reject;
policy: reject (enforced)
DKIM
no key found at common selectors

Certificate (current)

WE1
from 2026-04-18 to 2026-07-17
Expires in 43 days

HTTP security headers

Header hygiene 90/100 Checked live page: https://www.facilicomfoundation-samenvoorelkaar.nl/

present
  • strict-transport-security
  • content-security-policy
  • x-frame-options
  • x-content-type-options
  • referrer-policy
  • permissions-policy
findings
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
Header values
referrer-policy
strict-origin-when-cross-origin
x-frame-options
SAMEORIGIN
permissions-policy
accelerometer=(), camera=(), document-domain=(), fullscreen=(self), geolocation=(), gyroscope=(), magnetometer=(), microphone=(), midi=(), payment=(), usb=(), sync-xhr=(self)
x-content-type-options
nosniff
content-security-policy
default-src 'self' data: ; script-src 'self' 'report-sample' 'unsafe-eval' 'unsafe-inline' *.cloudfront.net *.google-analytics.com ssl.google-analytics.com www.google.com www.googleadservices.com www.googleoptimize.com *.googletagmanager.com www.gstatic.com tagmanager.google.com maps.googleapis.com *.doubleclick.net connect.facebook.net *.landbot.io webchat.digitalcx.com *.hotjar.com cdnjs.cloudflare.com stackpath.bootstrapcdn.com cdn.jsdelivr.net code.jquery.com onesignal.com cdn.onesignal.com ads.creative-serving.com googleads.g.doubleclick.net *.monsido.com js-agent.newrelic.com bam.eu01.nr-data.net nonce-9c516b84 ; style-src 'self' 'report-sample' blob: 'unsafe-inline' *.cloudfront.net fonts.googleapis.com cdn.jsdelivr.net onesignal.com cdn-images.mailchimp.com translate.googleapis.com *.landbot.io nonce-9c516b84 ; img-src 'self' data: blob: ssl.gstatic.com www.gstatic.com *.google-analytics.com *.google.com *.google.nl *.google.de *.google.be *.g.doubleclick.net maps.gstatic.com *
strict-transport-security
max-age=63072000; includeSubDomains preload

Links to (3)

Linked from (1)