fiod.nl
HTML metadata
Technology
- CMS
- WordPress
- jQuery
- 3.7.1
Third-party hosts loaded (2)
- f1-eu.readspeaker.com×2
- pwa001.belastingdienst.nl×2
Social
DNS records live
- NS
-
- ns2.belastingdienst.nl
- ns3.belastingdienst.nl
- ns4.belastingdienst.nl
- MX
-
- 10 smtp1.belastingdienst.nl
- 10 smtp2.belastingdienst.nl
- TXT
-
_op61j3m0p1n1cozvw5wx2dj72hzs9kj8F57-F46B-A3E9-D206-8B9C-CEAE-0802-4F93
Email authentication strong
- SPF
-
v=spf1 redirect=_spf.belastingdienst.nlmissing all - DMARC
-
v=DMARC1; p=reject; rua=mailto:dmarc.rua@belastingdienst.nl; sp=reject;policy: reject (enforced) · sp=reject - DKIM
- no key found at common selectors
Certificate (current)
DigiCert G2 TLS EU RSA4096 SHA384 2022 CA1
Expires in 153 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
same-origin- x-frame-options
SAMEORIGIN- permissions-policy
camera=(), geolocation=(), microphone=()- x-content-type-options
nosniff- content-security-policy
default-src https://www.fiod.nl/ 'self'; script-src https://pwa001.belastingdienst.nl https://www.fiod.nl/ https://app-eu.readspeaker.com/ https://f1-eu.readspeaker.com/ https://www.youtube.com/ 'unsafe-inline' 'unsafe-eval'; style-src https://f1-eu.readspeaker.com/ 'self' 'unsafe-inline'; img-src https://i.ytimg.com/ https://adobe-analytics-dc.belastingdienst.nl/ https://*.belastingdienst.nl 'self' data:; connect-src https://f1-eu.readspeaker.com/ https://app-eu.readspeaker.com/ https://vttts-eu.readspeaker.com/ https://rstts-eu.readspeaker.com/ https://vtdnntts-eu.readspeaker.com/ https://media-eu.readspeaker.com/ https://adobe-analytics-dc.belastingdienst.nl 'self'; font-src 'self' data:; frame-src https://www.youtube-nocookie.com/ https://vepapi.vcdn.belastingdienst.nl/; form-action https://app-eu.readspeaker.com/ 'self'; frame-ancestors 'none'; base-uri 'self'; upgrade-insecure-requests- strict-transport-security
max-age=31536000; includeSubdomains