geel.be
HTML metadata
Technology
Third-party hosts loaded (1)
- prod.widgets.burgerprofiel.vlaanderen.be×2
Social
Contact
DNS records live
- NS
-
- ns1.register.be
- ns2.register.be
- ns3.register.be
- MX
-
- 5 de-smtp-inbound-1.mimecast.com
- 5 de-smtp-inbound-2.mimecast.com
- TXT
-
Show 7 TXT records
have-i-been-pwned-verification=dweb_c7fza3038htva9c9blc15eqz6U68ADRCGM1GY4T2QXXT9DHJBS0SRNTHTZB1T5ZJcisco-ci-domain-verification=505c8833112f76cbe02fecb1d0dc9c099b7d9c97d5a1b03c7c34e3db4ea8c8fd_globalsign-domain-verification=f13Hnb27_BSLcZcSJDB2MRTNC_dxbucKxvUKrI9ctVbw=xSqigFv2qQqGeNu31Ki3PWwvtp2IFjEoHGdzo0odILJ70ed1fe018aa266b4b7934749459e73dd37714536eeMS=9A9C29FFC76D7EDBA4BE0E1444EED9515818BC48
Email authentication strong
- SPF
-
v=spf1 include:_u.geel.be._spf.smart.ondmarc.com -allstrict (-all) - DMARC
-
v=DMARC1; p=reject; pct=100; sp=reject; rua=mailto:38b7e1a6@inbox.ondmarc.com; ruf=mailto:38b7e1a6@inbox.ondmarc.com,mailto:soc@geel.be; adkim=r; aspf=r; fo=1; rf=afrf; ri=3600policy: reject (enforced) · sp=reject - DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDAFny8XBctPwY6ZIvibFfuQiTSiEmZrTWdp7a73ILNavKMX2TQeLqeC3lC4WrDY6f/NXjIgTnJ5WpSSAScM+… - selector2:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQC5+E+Gk/tWgszK5S2eIAGgApfsI0whkaJcePRwM2JD1Ub25DsNIWbXb+efZ82NnbAy6T7nVPiSSxSu19qR85…
selectors probed - selector1:
Certificate (current)
R13
Expires in 47 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN- permissions-policy
accelerometer=(), autoplay=*, camera=(), cross-origin-isolated=(), document-domain=(), encrypted-media=(), fullscreen=*, geolocation=*, gyroscope=(), magnetometer=(), microphone=(), midi=(), payment=(), picture-in-picture=*, publickey-credentials-get=(), screen-wake-lock=(), sync-xhr=*, usb=(), web-share=(), xr-spatial-tracking=(), clipboard-read=(), clipboard-write=()- x-content-type-options
nosniff- content-security-policy
default-src 'self' 'unsafe-inline' 'unsafe-eval' *.lcp.be *.icordis.be *.typeform.com *.google-analytics.com *.tile.openstreetmap.org *.googleapis.com *.gstatic.com *.uitdatabank.be *.imgix.net *.youtube.com *.ytimg.com *.vimeo.com *.vimeocdn.com *.twitter.com *.facebook.com *.fwebservices.be *.tile.openstreetmap.be *.widgets.burgerprofiel.vlaanderen.be *.vlaanderen.be *.frontend.burgerprofiel.vlaanderen.be *.tni.frontend.burgerprofiel.dev-vlaanderen.be *.widgetconfigservice.burgerprofiel.vlaanderen.be tni.widgets.burgerprofiel.dev-vlaanderen.be *.tni.widgets.burgerprofiel.dev-vlaanderen.be *.tni.contactapi.uat-vlaanderen.be tni.frontend.burgerprofiel.dev-vlaanderen.be *.contactapi.vlaanderen.be wss://authenticatie.vlaanderen.be *.cloudfront.net authenticatie.vlaanderen.be authenticatie-ti.vlaanderen.be *.googletagmanager.com https://region1.analytics.google.com *.osm.be *.readspeaker.com *.geel.be *.widget.enviso.io *.enviso.io *.checkoutshopper-live.adyen.com *.e.issuu.com *.issuu.co- strict-transport-security
max-age=31536000