gsportvlaanderen.be
HTML metadata
Technology
- Server
- nginx
- Cookie consent
-
- Cookiebot
- Fonts
-
- Google Fonts
Third-party hosts loaded (6)
- fonts.googleapis.com×2
- scripts.simpleanalyticscdn.com×2
- cdn1.readspeaker.com×1
- consent.cookiebot.com×1
- fonts.gstatic.com×1
- s7.addthis.com×1
Social
Contact
DNS records live
- NS
-
- ns1.european-server.eu
- ns3.european-server.com
- ns4.european-server.com
- MX
-
- 0 gsportvlaanderen-be.mail.protection.outlook.com
- TXT
-
domain-verification:5ed1069bbb84ffc11085450441a0773ac578edd5domain-verification:d779a9d3aea9ef35fdc0bd4e2cec17ffbe3b7d84P0R4O00328
- Verified for
-
- Brevo
Email authentication weak
- SPF
-
v=spf1 ip4:185.47.28.0/22 ip4:193.190.147.34 ip4:78.23.193.196 ip4:78.23.7.98 ip4:46.235.45.4 ip4:46.235.46.210 ip4:46.235.46.212 ip4:188.64.53.68 ip4:104.47.0.36 ip4:185.47.28.0/27 ip4:91.223.195.245 ip4:109.131.23.49 include:spf.protection.outlook.com include:sendgrid.net -allstrict (-all) - DMARC
- not published
- DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAsMN1PhE3vi8YRlYNI97206Gp1sjZQr655I4V3zsrb0g8Tkun0sPW+SjOmiIiPbWCjBz/32qXOAQN+G…
selectors probed - selector1:
Certificate (current)
Sectigo Public Server Authentication CA DV R36
Expires in 257 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Permissions Policy
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src 'self' 'unsafe-inline' *.parantee-psylos.be *.gsportvlaanderen.be *.google.com *.addthis.com *.bugherd.com *.pusher.com *.pusherapp.com *.cloudfront.net *.amazonaws.com; child-src blob:; connect-src 'self' *.gsportvlaanderen.be *.craftcms.com *.readspeaker.com *.mapbox.com *.tiles.mapbox.com api.mapbox.com *.bugherd.com *.pusher.com *.pusherapp.com *.addthis.com *.google.com *.googleapis.com *.google-analytics.com *.cookiebot.com *.simpleanalyticscdn.com *.juicer.io https://*.hotjar.com https://*.hotjar.io wss://*.hotjar.com; font-src 'self' data: *.googleapis.com *.bugherd.com *.google.com *.readspeaker.com *.gstatic.com *.juicer.io https://*.hotjar.com; frame-src *.parantee-psylos.be *.gsportvlaanderen.be *.twitter.com *.addthis.com *.facebook.com *.google.com *.googleapis.com *.googletagmanager.com *.vimeo.com *.youtube.com *.clevercast.com *.video-stream-hosting.de *.cookiebot.com *.nonki.dev; img-src 'self' data: *.gsportvlaanderen.be- strict-transport-security
max-age=31536000; includeSubDomains