jonglaan.nl
HTML metadata
Technology
- Server
- nginx
- Analytics
-
- Google Tag Manager
Third-party hosts loaded (4)
- dev.visualwebsiteoptimizer.com×1
- maps.googleapis.com×1
- static.zdassets.com×1
- www.googletagmanager.com×1
Social
Contact
- Phone
DNS records live
- NS
-
- ns1.kpn.net
- ns11.kpn.net
- MX
-
- 0 jonglaan-nl.mail.protection.outlook.com
- TXT
-
Show 5 TXT records
QuoVadis=9eaa5535-742f-448e-9e47-928ae62286d5lszNXo/Wd3r+7F/dPE16fT17p9yhZQ6AvGDEdk5wufOvFL/yZaiic3l+dkr/SlqMxg7zw8bpZ3eGDI0OK1GNzQ==hes=a5734e35dc370fa74e9c88cc562ff057QuoVadis=cbbb2cd7-79dc-4484-b9a7-a9b5d1475dcbDomainVerification=2JAHAQHY11SJ2HXWF8KU8BP8U8DUTBV4R6AO9YO927JS50CFUMA9981AZTVOFWXN
- Verified for
-
- Dynamics 365
- Microsoft 365
Email authentication weak
- SPF
-
v=spf1 ip4:87.249.116.224/28 include:spf.protection.outlook.com include:malengo.exception.mx include:spf.afas.online include:spf.mailjet.com ip4:46.31.48.0/21 ip4:195.143.61.129 ip4:192.254.119.131 include:_spf.paytsoftware.com ip4:81.18.160.92 ~allsoftfail (~all) - DMARC
- not published
- DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCmluFNpgG04OTUietTApQdJxs68sRz0/F9qNjlWbg+hXjSA922tTiRu3AshRiIsJ5GQ97FFb050mDoWtxD4J… - s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEArvrLm/7Br6K96cKkR1Fvk2qGr3fspJdyAVVs2x7XgNYfPGonIPx5o3HUqpDVVP9bx7kfGCb076U5Q2ixDk… - s2:
k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCufMI4axzUShqbjKP/5MsVjq0sk7NhUoEIJRdxl5sqPFB8Bs7yeSGaIngdNWMMWUGKr0ECQfgcCw0e/foMHiA/lx…
selectors probed - selector1:
Certificate (current)
R13
Expires in 62 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Referrer Policy
Header values
- x-frame-options
SAMEORIGIN- permissions-policy
geolocation=(), midi=(), notifications=(), push=(), sync-xhr=(), microphone=(), camera=(), magnetometer=(), gyroscope=(), speaker=(self), vibrate=(), fullscreen=(self https://*.youtube.com https://*.youtube-nocookie.com https://*.youtu.be), payment=()- x-content-type-options
nosniff- content-security-policy
default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://*.dynamics.com https://*.apollo.io https://*.clarity.ms https://sc-static.net https://*.gstatic.com https://*.run.app https://*.visualwebsiteoptimizer.com https://app.vwo.com https://cdn.pushcrew.com https://*.googlesyndication.com https://*.azureedge.net https://*.analytics.google.com https://*.doubleclick.net https://*.bing.com https://*.licdn.com https://*.googleadservices.com https://extreme-ip-lookup.com https://*.zopim.com https://cdnjs.cloudflare.com https://static.zdassets.com https://*.cookiebot.com https://*.googletagmanager.com https://*.googleapis.com https://*.google-analytics.com https://*.youtube.com https://*.youtube-nocookie.com https://*.youtu.be https://*.ytimg.com https://*.cookiebot.com https://*.pardot.com https://connect.facebook.net https://static.ads-twitter.com https://*.google.com https://analytics.twitter.com https://js.hsforms.net/forms/shell.js https://forms.hsforms.com/embed/ http- strict-transport-security
max-age=31536000; includeSubDomains