hrgroep.nl
HTML metadata
Technology
- Server
- nginx
- CMS
- Gatsby
- Analytics
-
- Google Tag Manager
- Fonts
-
- Google Fonts
Third-party hosts loaded (4)
- cdn.brevo.com×1
- fonts.googleapis.com×1
- www.facebook.com×1
- www.googletagmanager.com×1
Social
Contact
- Phone
- Address
- Frijdastraat 17-19, 2288 EX, Rijswijk, Nederland
DNS records live
- NS
-
- auth01.dns.trueserver.nl
- auth02.dns.trueserver.nl
- auth03.dns.trueserver.nl
- MX
-
- 0 hrgroep-nl.mail.protection.outlook.com
- TXT
-
0Dp/B0tYE4w3y0rdYVKrMxknPYLbvmSXD+RoI5PpRVetQ0CZhHHifzi0ngirMWgLfkqYqOPk/PadSAVlW9V4Xw==
- Verified for
-
- Brevo
- Microsoft 365
Email authentication strong
- SPF
-
v=spf1 include:spf.hrgroepprod.hypernode.io include:_spf.mailersend.net ip4:89.146.37.46 ip4:89.146.37.47 ip4:93.92.30.56/30 ip4:185.6.205.20/30 ip4:212.121.112.160 a:mailer.capitool.com include:_spf.exactonline.nl include:spf.protection.outlook.com include:mailplus.nl include:emsd1.com include:spf.icontroller.eu include:verbindalles.nl -allstrict (-all) - DMARC
-
v=DMARC1; p=reject; rua=mailto:administrator@hrgroep.nl,mailto:dmarc_agg@vali.email; fo=1; aspf=s;policy: reject (enforced) - DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAuGo6ylnWUKtmtbxdJqSrM0H+LIvw5UXXkdDKdJCp1UWO6NTy0ji9acXtggvW+Ph7Om/Q2RKbNswYdq… - selector2:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAn65CYX2GMnv6vUDkWnsGxvA/5EFBt+9TkUrtcgQHQFTE925Weaz8CFqdPsjUl1LmS2j9n0rWlUDmBx…
selectors probed - selector1:
Certificate (current)
E8
Expires in 31 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
strict-origin- x-frame-options
SAMEORIGIN- permissions-policy
geolocation=(), midi=(), sync-xhr=(), microphone=(), camera=(), magnetometer=(), gyroscope=(), fullscreen=(self), payment=()- x-content-type-options
nosniff- content-security-policy
font-src *.cloudflare.com *.twitter.com *.gstatic.com *.typekit.net *.twimg.com *.trustedshops.com *.googleapis.com *.google.com *.youtube.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.twitter.com *.google.com *.youtube.com maps.googleapis.com consult.esize.nl start.esize.nl *.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com player.vimeo.com https://www.google.com/recaptcha/ *.twitter.com *.google.com *.facebook.com maps.googleapis.com lightwidget.com *.m- strict-transport-security
max-age=31536000; includeSubDomains