heumen.nl

.nl crawl

First seen 2026-05-31 · Last seen 2026-06-01 · ok HTTP/1.1 200 868 ms crawled 2026-06-01

IE · 54.72.84.243 · AS16509 Amazon.com, Inc.

Reputation 100/100

Classifying

HTML metadata

Title
Home | Gemeente Heumen
Description
Dit is de officiële site van de gemeente Heumen. U kunt terecht voor informatie en online dienstverlening.
Language
nl
Generator
SIMsite powered by Drupal
Canonical
https://www.heumen.nl/

Open Graph

url
https://www.heumen.nl/
title
Home
locale
nl
site name
Gemeente Heumen
description
Dit is de officiële site van de gemeente Heumen. U kunt terecht voor informatie en online dienstverlening.
updated time
2026-04-29T16:07:06+02:00

Technology

CMS
Drupal
JS framework
Next.js

Third-party hosts loaded (3)

  • cuatro.sim-cdn.nl×68
  • fonts.bunny.net×1
  • heumen.logging.simanalytics.nl×1

Social

Contact

Phone

DNS records live

NS
  • ns.internlnet.nl
  • ns3.internl.net
  • ns4.internl.net
MX
  • 10 mx1.irvn.nl
  • 10 mx2.irvn.nl
TXT
Show 4 TXT records
  • v=NTA7516-1;startdate=2023-07;enddate=2026-06;provider=Zivver
  • u8dtXgBIark77HeiQlvqPipLu9LWowLqdC0AMguENa0KNHwz+a0BJutO6nS+XU9jReGFOSaFsWUC2lhEoUVWfA==
  • 9e6e400ef1727ef2be5b56f35af527c92c4940ad3096c90532ec6a577e3aec86
  • DomainVerification=SJ08UAN1YDP6IPQAZPDI3PW4PTPVWL01TQW3FKCP8PMRMJJVGBZO7QRB0V3HVOFW
Verified for
  • Adobe
  • Google
  • Microsoft 365

Email authentication strong

SPF
v=spf1 mx include:spf.protection.outlook.com include:_spf.zivver.com include:message.djuma.nl include:spf.simgroephosting.nl include:spf.pinkprivate.cloud include:spf.flowmailer.net a:malengo.exception.mx ~all
softfail (~all)
DMARC
v=DMARC1; p=reject; rua=mailto:zazbn0ui@ag.eu.dmarcadvisor.com; ruf=mailto:zazbn0ui@fr.eu.dmarcadvisor.com;
policy: reject (enforced)
DKIM
  • selector1: v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA19/Ku1HYfVxIKnWlmaQ7gqCr2A3yv8onlkp17P4kTYaNaz+JjzDAr0VGZVjzTVevU6DPSFdvWN4Okw…
  • selector2: v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAqecBmdAytSo0CVKEt339lZYRCr5cP7lo00zo5DfcIxoCFTLVne8M4YVQ4auv8N/mTnFFZoeNxmy57k…
  • k1: k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDbNrX2cY/GUKIFx2G/1I00ftdAj713WP9AQ1xir85i89sA2guU0ta4UX1Xzm06XIU6iBP41VwmPwBGRNofhBVR+e6WHUo…
selectors probed

Certificate (current)

Thawte TLS RSA CA G1
from 2025-11-26 to 2026-11-26
Expires in 177 days

HTTP security headers

Header hygiene 75/100 Checked live page: https://www.heumen.nl/

present
  • strict-transport-security
  • content-security-policy
  • content-security-policy-report-only
  • x-content-type-options
  • referrer-policy
findings
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
  • missing frame protection
  • missing Permissions Policy
Header values
referrer-policy
same-origin
x-content-type-options
nosniff
content-security-policy
default-src 'self'; img-src * data: 'unsafe-inline' blob:; style-src * 'unsafe-inline' blob:; font-src * data:; script-src * 'unsafe-inline' 'unsafe-eval'; connect-src *; form-action *; media-src *.readspeaker.com *.streamlock.net *.archieven.nl storage.googleapis.com scribit-pro-hosting.storage.googleapis.com scribit-pro.storage.googleapis.com app.talkjs.com *.bbvms.com *.cloudfront.net data: 'self' blob:; frame-src *; frame-ancestors 'self' https://*.polly.help; worker-src * 'unsafe-inline' blob:;
strict-transport-security
max-age=31536000
content-security-policy-report-only
default-src 'self'; img-src * data: blob:; style-src * 'unsafe-inline' blob: https://fonts.bunny.net https://*.tolkie.nl; font-src 'self' data: https://fonts.bunny.net https://fonts.gstatic.com https://cuatro.sim-cdn.nl https://cuatro.sim-cdn-acceptatie.nl https://cuatro.sim-cdn-test.nl https://*.tolkie.nl; script-src 'nonce-MzhkOGUzNGYtYmM3MS00MGI4LThmOTAtOTAyMTdiODlhYzk1' 'strict-dynamic' 'report-sample'; connect-src *; form-action 'self'; media-src https://*.readspeaker.com https://*.streamlock.net https://storage.googleapis.com https://scribit-pro-hosting.storage.googleapis.com https://scribit-pro.storage.googleapis.com https://app.talkjs.com 'self' blob:; frame-src *; frame-ancestors 'self' https://*.polly.help; worker-src * 'unsafe-inline' blob:; report-uri /api/csp-report

Links to (5)

Linked from (1)