immoscoop.be
HTML metadata
Technology
- CDN
- Amazon CloudFront
- CMS
- Next.js
- JS framework
- Next.js
- Analytics
-
- Google Tag Manager
- Fonts
-
- Google Fonts
Third-party hosts loaded (5)
- fonts.googleapis.com×5
- fonts.gstatic.com×3
- cdnjs.cloudflare.com×2
- px.gumgum.com×2
- www.googletagmanager.com×1
DNS records live
- NS
-
- ns1.eurodns.com
- ns2.eurodns.com
- ns3.eurodns.com
- ns4.eurodns.com
- MX
-
- 10 aspmx.l.google.com
- 20 alt1.aspmx.l.google.com
- 20 alt2.aspmx.l.google.com
- 30 alt3.aspmx.l.google.com
- 30 alt4.aspmx.l.google.com
- Verified for
-
- Atlassian
- Meta
- Microsoft 365
Email authentication strong
- SPF
-
v=spf1 include:_spf.google.com include:mail.zendesk.com include:emsd1.com +a +mx -allstrict (-all) - DMARC
-
v=DMARC1; p=quarantine; rua=mailto:dmarc@thenextimmoscoop.be,mailto:re+8a5c6c2a1093@inbound.dmarcdigests.compolicy: quarantine - DKIM
-
- k2:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAv2aC2KjGKLOwTweBY5A9RpjsxaBXR9r7OAU6U8/zn92ivImI75naUujWbItRI/QmL1jy5PWGqLwoUA… - s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAvhMvgI4mE0v9TuAVPEryi4i1Flja4euz8FeLQD7827va0xGln4Uio+8iKr+nLSDguut6IDu1fhirNAAvXD… - s2:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAxeUiZ/lGCqmX0tkFN0LDrRQNcHM+NbSY7i4DWazmwrBPKEsVy3omHKOpYF3dTh6iRjvYWqw+vriEI0kF5g…
selectors probed - k2:
Certificate (current)
Amazon RSA 2048 M04
Expires in 111 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing frame protection
- missing content type protection
- missing Referrer Policy
- missing Permissions Policy
Header values
- content-security-policy
default-src 'self' immoscoop.be *.immoscoop.be *.www1.immoscoop.be kbc.be *.kbc.be *.sentry.io *.colibry.cloud production-co-libry.appspot.com googletagmanager.com *.googletagmanager.com *.hotjar.com *.hotjar.io *.cookiepro.com *.cloudflare.com *.gstatic.com *.cloudfront.net *.googlesyndication.com googleoptimize.com *.googleoptimize.com *.googleapis.com google.com *.google.com *.google-analytics.com *.licdn.com *.facebook.net facebook.com *.facebook.com *.linkedin.com *.bing.com *.doubleclick.net *.a.run.app 'unsafe-inline' 'unsafe-eval' *.jsdelivr.net *.googleadservices.com analytics.tiktok.com *.onetrust.io *.onetrust.com *.mapbox.com *.maptiler.com *.storyblok.com *.oribi.io *.adobedtm.com *.outbrain.com *.optimonk.com *.clarity.ms *.cookiebot.eu *.cookiebot.com *.eu-central-1.amazonaws.com *.youtube.com *.youtube-nocookie.com *.powerbi.com *.intercom.io *.intercom.com *.intercomcdn.com redditstatic.com *.redditstatic.com tglyr.co *.tglyr.co adnxs.com *.adnxs.com pixel-config.redd- strict-transport-security
max-age=31536000; includeSubDomains; preload
Links to (2)
- google.com×1
- apple.com×1