giveaday.eu

.eu crawl

First seen 2026-05-24 · Last seen 2026-05-31 · ok HTTP/1.1 200 4993 ms crawled 2026-05-29

NL · 23.97.214.87 · AS8075 Microsoft Corporation

Reputation 92/100 no dmarc policy

Classifying

HTML metadata

Title
Voluntary work for volunteers and organizations
Description
Find your ideal volunteering match. An extensive range of 4000+ vacancies for volunteers. An initiative with the support of Belgian cities and municipalities
Language
en
Canonical
https://www.giveaday.eu/en-be
Translations
  • en ×3
  • fr ×3
  • nl

Open Graph

url
https://www.giveaday.eu/en-be
title
Voluntary work for volunteers and organizations
description
Find your ideal volunteering match. An extensive range of 4000+ vacancies for volunteers. An initiative with the support of Belgian cities and municipalities

Technology

CDN
Cloudflare
CMS
Nuxt
JS framework
Nuxt
Social widgets
  • YouTube Embed

Third-party hosts loaded (3)

  • d1bnv20w2037a.cloudfront.net×32
  • cdnjs.cloudflare.com×1
  • www.youtube.com×1

Social

DNS records live

NS
  • sean.ns.cloudflare.com
  • tricia.ns.cloudflare.com
MX
  • 0 giveaday-eu.mail.protection.outlook.com
TXT
  • mailerlite-domain-verification=c04374ef1c8dbdb42b57ce5d571a5e19846fd7e4
Verified for
  • Google

Email authentication weak

SPF
v=spf1 include:spf.protection.outlook.com include:_spf.mlsend.com ~all
softfail (~all)
DMARC
not published
DKIM
  • smtpapi: k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDPtW5iwpXVPiH5FzJ7Nrl8USzuY9zqqzjE0D1r04xDN6qwziDnmgcFNNfMewVKN2D1O+2J9N14hRprzByFwfQW76…
selectors probed

Certificate (current)

R12
from 2026-04-21 to 2026-07-20
Expires in 49 days

HTTP security headers

Header hygiene 90/100 Checked live page: https://www.giveaday.eu/en-be

present
  • strict-transport-security
  • content-security-policy
  • x-frame-options
  • x-content-type-options
  • referrer-policy
  • permissions-policy
  • cross-origin-opener-policy
  • cross-origin-embedder-policy
  • cross-origin-resource-policy
findings
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
Header values
referrer-policy
strict-origin-when-cross-origin
x-frame-options
DENY
permissions-policy
accelerometer=(), autoplay=(*), camera=(self), display-capture=(), encrypted-media=(self https://www.youtube.com https://www.youtube-nocookie.com https://player.vimeo.com), fullscreen=(self https://www.youtube.com https://www.youtube-nocookie.com https://player.vimeo.com), geolocation=(self), gyroscope=(), magnetometer=(), microphone=(self), midi=(), payment=(), picture-in-picture=(*), publickey-credentials-get=(), screen-wake-lock=(), sync-xhr=(self), usb=(), web-share=(), xr-spatial-tracking=()
x-content-type-options
nosniff
content-security-policy
base-uri 'none'; default-src 'self'; connect-src 'self' https: ws: capacitor://* https://www.google.com https://www.gstatic.com; font-src 'self' https: data:; form-action 'self'; frame-ancestors *; frame-src 'self' https://www.youtube.com https://www.youtube-nocookie.com https://player.vimeo.com https://www.google.com https://www.gstatic.com https://www.googletagmanager.com; img-src 'self' https: data:; manifest-src 'self'; media-src 'self'; object-src 'none'; script-src-attr 'none'; style-src 'self' https: 'unsafe-inline'; script-src 'self' 'nonce-dtClVl5fDTVorAcFAqjQ5ism' 'strict-dynamic' 'unsafe-inline' https://d1bnv20w2037a.cloudfront.net https://www.gstatic.com https://www.google.com https://www.googletagmanager.com 'unsafe-eval'; upgrade-insecure-requests; worker-src 'self' blob:; report-uri https://o431102.ingest.us.sentry.io/api/5381141/security/?sentry_key=84af06c466c7471ca375e32911588ae9;
strict-transport-security
max-age=63072000; includeSubDomains; preload
cross-origin-opener-policy
same-origin
cross-origin-embedder-policy
unsafe-none
cross-origin-resource-policy
cross-origin

Links to (5)

Linked from (2)