gouda.nl

.nl crawl

First seen 2026-05-22 · Last seen 2026-05-31 · ok HTTP/1.1 200 12510 ms crawled 2026-05-28

NL · 185.144.224.28 · AS20847 Previder B.V.

Reputation 100/100

Classifying

HTML metadata

Title
Gemeente Gouda
Language
nl-NL
Canonical
https://www.gouda.nl/
Feeds

Open Graph

url
https://www.gouda.nl/
title
Gemeente Gouda
locale
nl_NL
site name
Gemeente Gouda

Technology

CMS
WordPress

Third-party hosts loaded (3)

  • kit.fontawesome.com×2
  • gmpg.org×1
  • meldingen.hollandsmiddenveilig.nl×1

Social

Registration

Registrar
team.blue nl B.V.
Created
1996-09-22
Updated
2021-11-04
Name servers
  • ns1.transip.nl
  • ns0.transip.net
  • ns2.transip.eu

DNS records live

NS
  • ns0.transip.net
  • ns1.transip.nl
  • ns2.transip.eu
MX
  • 5 gouda-nl.r-v1.mx.microsoft
TXT
Show 5 TXT records
  • intersight=91071391a6e681808ce5b072d8d16198e4a291e7409c657d118ee3d674dfe167
  • v=NTA7516-1;startdate=2021-12;enddate=2030-01;provider=Zivver
  • sophos-domain-verification=afde6da461d8c2313f4b02266c39f985f80721f42afdf491536a77ee30a233dc
  • kyuD4AlKEH11CZe3WgRRCD+/l6BhQieZRps+bE0uO+k=
  • DomainVerification=8YU2KBLSTITBSSBW9CO1YBG2MQGTEA0W5R42NUXU89CO22TMCLOA8XN8ZW9DQC9Y
Verified for
  • Apple
  • Brevo
  • Google
  • Microsoft 365

Email authentication strong

SPF
v=spf1 ip4:45.85.148.5 ip4:80.69.74.48 ip4:91.231.6.241 ip4:91.230.244.106 ip4:77.74.54.216 ip4:212.35.124.164 include:spf.zaaksysteem.nl include:_spf.services.centric.eu include:_spf1.gouda.nl include:spf.protection.outlook.com -all
strict (-all)
DMARC
v=DMARC1; p=quarantine; rua=mailto:rapportages@dmarc.ibdgemeenten.nl;
policy: quarantine
DKIM
Show 5 DKIM selectors
  • selector1: v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDSr58nhfag+qW9YIpueP4qs3MGHiAqWhjumSp7iu2o6d9plJijU62/4dxVCKtks8p4SuYkbLo3xchU/1ZxB5…
  • selector2: v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCcW4oVW2XHp0vgD55MyZFxSSFqurX4c0XVk4bhGrvd3J5OtHJAVSee4+9y5K+ptijtVBYp+wcq/3ID3BkHji…
  • mail: k=rsa;p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDeMVIzrCa3T14JsNY0IRv5/2V1/v2itlviLQBwXsa7shBD6TrBkswsFUToPyMRWC9tbR/5ey0nRBH0ZVxp+lsmTxid2Y2z…
  • s1: k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAuQUKw9ZQopeDE1tfqKIlXqGR2NASwxcs6tDRPm8O/sa7xTz+b6zbJc91/0IKzE1F0q1liWF3KXGRL1rKLT…
  • s2: k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDJ8LVndfopPAfg2aFoeTl48096mmuECB2e7FtQPK+RXn/82k29hWUobcMdaVkbg5cg+amh9ESpSfP5dzBt9BVDlS…
selectors probed

Certificate (current)

Sectigo Public Server Authentication CA OV R36
from 2025-11-04 to 2026-12-04
Expires in 186 days

HTTP security headers

Header hygiene 80/100 Checked live page: https://www.gouda.nl

present
  • strict-transport-security
  • content-security-policy
  • x-frame-options
  • x-content-type-options
  • referrer-policy
  • permissions-policy
findings
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
  • weak frame protection
  • weak content type protection
Header values
referrer-policy
strict-origin-when-cross-origin
x-frame-options
sameorigin, SAMEORIGIN
permissions-policy
accelerometer=(self), autoplay=(self), camera=(self), cross-origin-isolated=(self), document-domain=*, encrypted-media=(self), fullscreen=(self), geolocation=(self), gyroscope=(self), magnetometer=(self), microphone=(self), midi=(self), payment=(self), picture-in-picture=*, publickey-credentials-get=(self), screen-wake-lock=(self), sync-xhr=*, usb=(self), xr-spatial-tracking=(self)
x-content-type-options
nosniff, nosniff
content-security-policy
connect-src 'self' elasticsearch-yard.app.owc.shockapp.io *.fontawesome.com *.googleapis.com *.google-analytics.com *.readspeaker.com *.siteimprove.com elasticsearch-yard-staging.app.owc.shockapp.io cdn1.readspeaker.com fonts.googleapis.com meldingen.hollandsmiddenveilig.nl www.google.com; default-src 'self'; font-src 'self' data: https:; frame-src 'self' https://www.google.com https://www.youtube.com https://www.youtube-nocookie.com https://player.vimeo.com https://indiveo.services; img-src data: https:; media-src 'self'; object-src data: https:; script-src 'self' 'unsafe-inline' 'unsafe-eval' data: https:; script-src-elem 'self' 'unsafe-inline' 'unsafe-eval' *.fontawesome.com *.googleapis.com *.googletagmanager.com *.gstatic.com *.readspeaker.com *.siteimprove.net connect.facebook.net siteimproveanalytics.com translate.google.com meldingen.hollandsmiddenveilig.nl www.google.com www.google-analytics.com www.gstatic.com nl.postex.com; style-src 'self' 'unsafe-inline' *.googleapis.com w
strict-transport-security
max-age=31536000; includeSubDomains

Links to (9)

Linked from (4)