jeraonair.nl
HTML metadata
Technology
- Server
- nginx
Third-party hosts loaded (2)
- i.ytimg.com×343
- cdn.lightwidget.com×2
Social
DNS records live
- NS
-
- ns1.cybox.nl
- ns2.cybox.eu
- MX
-
- 1 aspmx.l.google.com
- 10 alt3.aspmx.l.google.com
- 5 alt1.aspmx.l.google.com
- 5 alt2.aspmx.l.google.com
- Verified for
-
Email authentication partial
- SPF
-
v=spf1 a include:_spf.google.com include:spf.antispamcloud.com include:servers.mcsv.net ?allneutral (?all) - DMARC
-
v=DMARC1; p=none;policy: none (monitoring only) - DKIM
-
- google:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAv0sfp3dV4sHn0tm91qvyH0WZPqxiBtnyqWy4WNI4EyisGvxK60oU+oIP0I24z5en4fpwWOX+MUOt6S… - k1:
k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDbNrX2cY/GUKIFx2G/1I00ftdAj713WP9AQ1xir85i89sA2guU0ta4UX1Xzm06XIU6iBP41VwmPwBGRNofhBVR+e6WHUo…
selectors probed - google:
Certificate (current)
R12
Expires in 61 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-content-type-options
- referrer-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing frame protection
- missing Permissions Policy
Header values
- referrer-policy
strict-origin-when-cross-origin- x-content-type-options
nosniff- content-security-policy
default-src 'self'; style-src 'self' 'unsafe-inline' fonts.googleapis.com; script-src 'nonce-6c9bbac3162fe82a8fe6de9dd24135f8' 'strict-dynamic' 'self' https: 'unsafe-inline'; img-src 'self' data: i.ytimg.com i.vimeocdn.com www.googletagmanager.com https://*.google-analytics.com https://*.googletagmanager.com https://*.googleapis.com https://*.gstatic.com *.google.com *.googleusercontent.com analytics.twitter.com t.co alb.reddit.com *.snapchat.com imgsct.cookiebot.com *.googlesyndication.com *.google.nl *.facebook.com; frame-src 'self' www.youtube.com player.vimeo.com www.googletagmanager.com *.google.com *.snapchat.com consentcdn.cookiebot.com *.lightwidget.com https://www.facebook.com/; connect-src 'self' www.googletagmanager.com www.google.com https://*.analytics.google.com https://*.googletagmanager.com https://*.google-analytics.com https://*.googleapis.com *.google.com https://*.gstatic.com data: blob: pixel-config.reddit.com pixels.spotify.com *.cookiebot.com *.snapchat.com *.goo- strict-transport-security
max-age=63072000; includeSubDomains
Links to (50)
- zekeyou.com×1
- youtube.com×1
- x.com×1
- weareunpeople.com×1
- wcarband.com×1
- volkflannel.com×1
- vitelia.nl×1
- venray.nl×1
- vboysstockholm.com×1
- upchuckatlanta.com×1
- turbonegro.com×1
- trivium.org×1
- trashboat.co.uk×1
- tornfromoblivion.com×1
- tiktok.com×1
- thesundaysadness.com×1
- thesmithstreetband.com×1
- theonlybandever.com×1
- themenzingers.com×1
- theflatliners.com×1
- thedwarves.com×1
- thebaboonshow.com×1
- theatarisband.com×1
- teunissen-bv.nl×1
- talco-punkchanka.com×1
- suicidaltendenciesofficial.com×1
- sugarspineofficial.com×1
- strictbpm.com×1
- spotify.com×1
- setitoffband.com×1
- riseagainst.com×1
- reddit.com×1
- raincitydrive.com×1
- quicksandnyc.com×1
- periphery.net×1
- pennywisdom.com×1
- paparoachmerch.com×1
- paceshifters.com×1
- ourmirage.de×1
- offspring.com×1
- noisebringer.de×1
- nevertelband.com×1
- myshopify.com×1
- mouthculture.com×1
- mlvltd.com×1
- merchstore.nl×1
- melroseavenueband.com×1
- magnoliaparkband.com×1
- limburg.nl×1
- komi.io×1