halderberge.nl
HTML metadata
Technology
- CMS
- Drupal
- JS framework
- Next.js
Third-party hosts loaded (3)
- cuatro.sim-cdn.nl×69
- fonts.bunny.net×1
- halderberge.logging.simanalytics.nl×1
Social
DNS records live
- NS
-
- ns0.transip.net
- ns1.transip.nl
- ns2.transip.eu
- MX
-
- 10 halderberge-nl.y-v1.mx.microsoft
- TXT
-
Show 29 TXT records
iYW64pzk7lDXQ92xegKzp7TwVp68MtbMEFjQefEa7IzIz6GB0NBmmLkdo3cORL8K9Ol994umBzTAaxJkfJSDUZS5pRerFyauRmqAMit1MjUcCO3GTJVqBWHxGyzMBEQtyntGAtyiHkcfGGwgjj7C0aZOFnQFxGrWchnm7JNWyWwOOUaceBeh1lveLkm9a1fT_bocqspn2761w7basgncnbizodhxdquiF99UW5MTr8MD2PGGahDUpxzjuehRLDSyTI86tEVtjMuKaIAXTjFaMgRbmpMIHEslo2jBaEfQOGSkPC6xJnoJtPv4YpIz0Yh7HrZc6e3CJzU0uW6SJ7gaytdnq3bjDvWwoE8MkIssASDmDCbfG8pcWKG6zO2I7DVvqwHQyOF78urQz6bDUMi2YmAXt9uqmpW2BvFQ0rly0Q2e08gZDkOfcosbKBq94alehxUsj3PfkHrsJdsOukvnELim87YcBGMrm43ofuMWFLGiBlAVjzzdSa27pOMd2AuNLcYCBTrINZKal8S1IwN7rYTLROBg7hKrd2c92b3f8baea0b7d149f0172e00e12600c7652c7a60f74d910be94ba2f33233GOQNdQisOtbqYyErAHh0R2fWfl6ba98kFWYPy5aiuGe3XIeSiYjvB0BVaVYnZqMue62a91f69f23689f8054ecd17f44e80a632f285cc882ab67aa76176b5fa7bc43_4eyvqqg7gvtvpq81ng73s2ihbdq10t56qQxFjgitSYtqmFFPRE9z3oYErvQOg2HcN4KJOzTBNoQKgXdA2B2aRWJRmovzgZEaae46b8cc8fe9044805c4f2ca45e8f981bab6656a194d9a2fc391edc7dd67b90842903102267567157e45f877f58488a68fadd9dd7038ee903a694b347fd76c7_jrlvmogspcoidi1l8zj1bf121axgyvza155e9ae5107e4402f00d69ca2b06e41775f1b0867c387416a200d794266e8c1RrnWElvsq4ofVBmaMITlubVAvuEmbXLTJ9BFuht0O935p1sINb99sm9nV3jPjhmbwCIhSPMV6NUeVIANIoRcFwrfeeKwg8JQmbOofMJhURKCk3SGjHNP7ocKPtN0VwMrv=NTA7516-1;startdate=2023-06;enddate=2026-06;provider=zorgmail;ntamx=10 relay.zorgmail.nlwqsprETSnNvfrCHFzIuDUiOBdav5Lqce3rdtD7oJMrZjfaHwTtEdMK4JBYte678pTv8HxDRbA22fhmGRVJK6Dz50DRYoaRnA3wtzhxcLbuirOwiNEWoX48Ewn77HwfLCFKFay0XpZGv9Yf81Kivt/VuGDoWrIwMczyMB23RJ+1coonXhdX6xG6GxRBkHZv9+BiJTJsLAPg3d8sN6zsiv3ag==AooXC9e26ywnwIz6k0n09ykTQd518q4BvBtRszMWeQ1BCArLW26H8SGrBrYJygCA_dz3rekrhln2rz9bn3xas9fccvbvw8obv58XeqRP1GcLUqYTy8EYN2uRjQFTIldJiWrwT8M5yp9uhAehTjBWQV6PTMRWL6yi352FNSBN3zakGn+TVK+kSX4NpIReRf//nu47urdiYew=L9Jn5zM2Xfr3YJLsJsHJgHpnvgYVCuKSus5cizyIpjmVeTcc86LsTNbioHjG5xTt
- Verified for
-
- Apple
- Microsoft 365
Email authentication strong
- SPF
-
v=spf1 include:kkdwhx0um1.powerspf.com include:_spf.zorgmail.nl ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=reject; rua=mailto:ivwy7eiq@ag.eu.dmarcadvisor.com; ruf=mailto:ivwy7eiq@fr.eu.dmarcadvisor.com;policy: reject (enforced) - DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAw5dxJ+sqBS63Is/h1SIeg2EvpBt+mRcVPjPUTn5yS4w26ACGAfi48HZivNSvumG3jTZcuCYSOK1wa2… - selector2:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAuRZ9aQZOPZ0FcSM0qDRf0oPx8BlCvQxlL/akb0GcDSlcgqZzehpY3zvPtGiQw/P8nTIeNVYlZz7IP9…
selectors probed - selector1:
Certificate (current)
Thawte TLS RSA CA G1
Expires in 47 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- content-security-policy-report-only
- x-content-type-options
- referrer-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing frame protection
- missing Permissions Policy
Header values
- referrer-policy
same-origin- x-content-type-options
nosniff- content-security-policy
default-src 'self'; img-src * data: 'unsafe-inline' blob:; style-src * 'unsafe-inline' blob:; font-src * data:; script-src * 'unsafe-inline' 'unsafe-eval'; connect-src *; form-action *; media-src *.readspeaker.com *.streamlock.net *.archieven.nl storage.googleapis.com scribit-pro-hosting.storage.googleapis.com scribit-pro.storage.googleapis.com app.talkjs.com *.bbvms.com *.cloudfront.net data: 'self' blob:; frame-src *; frame-ancestors 'self' https://*.polly.help; worker-src * 'unsafe-inline' blob:;- strict-transport-security
max-age=31536000- content-security-policy-report-only
default-src 'self'; img-src * data: blob:; style-src * 'unsafe-inline' blob: https://fonts.googleapis.com; font-src 'self' data: https://fonts.bunny.net https://fonts.gstatic.com https://cuatro.sim-cdn.nl https://cuatro.sim-cdn-acceptatie.nl https://cuatro.sim-cdn-test.nl; script-src 'nonce-MzQ3ZTA4M2YtM2VhMC00ZWE0LTgyNTItMmM3MWEzODc0OGZl' 'strict-dynamic' 'report-sample'; connect-src *; form-action 'self'; media-src https://*.readspeaker.com https://*.streamlock.net https://storage.googleapis.com https://scribit-pro-hosting.storage.googleapis.com https://scribit-pro.storage.googleapis.com https://app.talkjs.com 'self' blob:; frame-src *; frame-ancestors 'self' https://*.polly.help; worker-src * 'unsafe-inline' blob:; report-uri /api/csp-report