hkz.nl

.nl crawl

First seen 2026-05-16 · Last seen 2026-05-20 · ok HTTP/1.1 200 3479 ms crawled 2026-05-20

NL · 20.160.224.69 · AS8075 Microsoft Corporation

Reputation 92/100 no dmarc policy

Classifying

HTML metadata

Title
Homepage - HKZ
Description
Basis voor beter - Een HKZ-certificaat laat zien dat jij voortdurend jouw zorg- en dienstverlening verbeterd en de klant centraal staat.
Language
nl-NL
Generator
WPML ver:4.9.2 stt:37;
Canonical
https://www.hkz.nl/
Translations
  • nl

Open Graph

url
https://www.hkz.nl/
title
Homepage - HKZ
locale
nl_NL
site name
HKZ
description
Basis voor beter - Een HKZ-certificaat laat zien dat jij voortdurend jouw zorg- en dienstverlening verbeterd en de klant centraal staat.

Technology

Server
nginx
CMS
WordPress 4.9.2 outdated (current 6.8)
jQuery
3.7.1

Third-party hosts loaded (3)

  • wpn.nen.nl×33
  • cdnjs.cloudflare.com×2
  • www.google.com×2

Social

Contact

Email
Phone

Registration

Registrar
Registrar.eu
Created
1998-12-29
Updated
2025-12-20
Name servers
  • ns3.openprovider.eu
  • ns2.openprovider.be
  • ns1.openprovider.nl

DNS records live

NS
  • ns1.openprovider.nl
  • ns2.openprovider.be
  • ns3.openprovider.eu
MX
  • 10 hkz-nl.mail.protection.outlook.com
Verified for
  • Microsoft 365

Email authentication weak

SPF
v=spf1 include:spf.protection.outlook.com -all
strict (-all)
DMARC
not published
DKIM
  • selector1: v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAxtUegu4dB4RzQL+zmCSbczxZI+K6Eut4MwKn+nazP4BI4DSHO1/EYJ3S35Ge3idtMkztwmSA/50vtC…
selectors probed

Certificate (current)

Sectigo Public Server Authentication CA DV R36
from 2026-03-02 to 2027-04-02
Expires in 316 days

HTTP security headers

Header hygiene 95/100 Checked live page: https://www.hkz.nl/

present
  • strict-transport-security
  • content-security-policy
  • x-frame-options
  • x-content-type-options
  • referrer-policy
  • permissions-policy
findings
  • CSP allows unsafe inline scripts/styles
Header values
referrer-policy
no-referrer-when-downgrade
x-frame-options
SAMEORIGIN
permissions-policy
interest-cohort=()
x-content-type-options
nosniff
content-security-policy
default-src 'self' https: ws: wss: data: blob: 'unsafe-inline'; frame-ancestors 'self'; script-src https: data: 'self' 'unsafe-inline' 'unsafe-eval';
strict-transport-security
max-age=31536000; includeSubDomains; preload

Links to (4)

Linked from (2)