heist-op-den-berg.be
HTML metadata
Technology
Third-party hosts loaded (1)
- fonts.icordis.be×2
Social
Contact
- Phone
DNS records live
- NS
-
- ns.cipal.be
- ns2.cipal.be
- MX
-
- 0 heistopdenberg-be01cbb.mail.protection.outlook.com
- TXT
-
sophos-domain-verification=b05b3ddf4a4246d4293e2b4d603e995ff8638b4fecacad448145dfcdf6604698
- Verified for
-
- Apple
- Brevo
- GlobalSign
- Microsoft 365
Email authentication partial
- SPF
-
v=spf1 include:spf.protection.outlook.com include:spf.ciport.be ip4:194.78.224.212 ip4:212.72.62.129 include:spf.lcp.be ip4:193.110.252.76 include:_spf.bibliotheek.be include:_spf_eucentral1.prod.hydra.sophos.com -allstrict (-all) - DMARC
-
v=DMARC1; p=none;rua=mailto:rua@heist-op-den-berg.bepolicy: none (monitoring only) - DKIM
-
Show 5 DKIM selectors
- selector1:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDnMX6RpR8E4ybX4bRssIXmUsqAtRCrDRW1mJPWkF/BUyQtcOTJVYiUEp82U8SdKfq4gXd2srMi8owIzZf2VR… - selector2:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCvwDceO73Bh6RleWecyUpYLt8Kt2lqAhg6D1Y1v3HloDKakHDVLXFpI1Gv1heNBJdhrpdgitmZ4tb0jlQ/dX… - k2:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAv2aC2KjGKLOwTweBY5A9RpjsxaBXR9r7OAU6U8/zn92ivImI75naUujWbItRI/QmL1jy5PWGqLwoUA… - s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA2H/meE4ZjDIIzS/aABzJYGuHAIu6leak2wIARVw6YmFCVl1xbF6fMFsVfj52rbi2xV6Is3gmwM7qXfb/ri… - s2:
k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDiSamGKCGzfh3O0rLkT8fzTxg2bddtxcI9p/vr0d2UqedQBkDrsIV2QyA+ow8ZGEmwr6TAcuDzmP8lbRLzCIRrHX…
selectors probed - selector1:
Certificate (current)
R12
Expires in 39 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP uses wildcard sources
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN- permissions-policy
accelerometer=*, autoplay=*, camera=*, cross-origin-isolated=*, encrypted-media=*, fullscreen=*, geolocation=*, gyroscope=*, magnetometer=*, microphone=*, midi=(), payment=*, picture-in-picture=*, publickey-credentials-get=*, screen-wake-lock=(), sync-xhr=*, usb=(), xr-spatial-tracking=self, clipboard-read=*, clipboard-write=*- x-content-type-options
nosniff- content-security-policy
connect-src 'self' https://heist-op-den-berg.icordis.be burgerprofiel.vlaanderen.be wss://authenticatie.vlaanderen.be wss://prod.widgets.burgerprofiel.vlaanderen.be https://prod.widgets.burgerprofiel.vlaanderen.be wss://prod.contactapi.uat-vlaanderen.be https://prod.contactapi.uat-vlaanderen.be https://contactapi.vlaanderen.be wss://contactapi.vlaanderen.be *.burgerprofiel.be widgets.vlaanderen.be geoserver.gis.cloud.mow.vlaanderen.be api.gipod.vlaanderen.be geo.api.vlaanderen.be *.toerismevlaanderen.be fonts.googleapis.com *.gstatic.com *.vrijwilligerswerk.be *.algolianet.com *.algolia.net yastatic.net *.jobsolutions.be *.enviso.io *.adyen.com *.timeblockr.com *.api.timeblockr.cloud wss://*.timeblockr.cloud *.signalr.timeblockr.cloud *.google-analytics.com *.googletagmanager.com stats.g.doubleclick.net *.analytics.google.com *.google.be td.doubleclick.net *.arcgis.com *.readspeaker.com https://performance.typekit.net *.giveaday.be *.giveaday.eu https://stats.- strict-transport-security
max-age=31536000