klaverblad.nl
HTML metadata
Technology
- Server
- Apache
- CMS
- Gatsby
- Analytics
-
- Google Tag Manager
Third-party hosts loaded (1)
- www.googletagmanager.com×1
Social
DNS records live
- NS
-
- ns1.capitar.dnsprov.com
- ns1.capitar.dnsprov.de
- ns1.capitar.dnsprov.eu
- MX
-
- 10 klaverblad-nl.mail.protection.outlook.com
- TXT
-
Show 8 TXT records
6RKx4Qu92g1AjjQf9CFN+rrmEFMBuvAyRZkXMeG4jxaWlUi1EGW3kSQukTTEg9jA/uRWnRH/7j0dPWABikA6fw==MS=1159FC326781C34F2F6FFA41316E7FFA1AADF872331wnksn76xh3scc7jk776vswrpcyr29rT4CVmDPe17AfQTEaQxfa40uBB5w3c1s21NTjVkRTY0=tlnd35FBMuwNgzG+XywvGVn7Wka2ZRRtp8Orhd0uHUk=7vfbxghk087l9f2x0jzj5c43f48b9zksQuoVadis=3fe48b91-cea8-40bc-8a21-fa089dced585H9vWR1Ye8NcdIKwvuw/ym3fksOfXxTjrOfrscu0jPXg=
- Verified for
-
- Atlassian
- Meta
- Microsoft 365
Email authentication partial
- SPF
-
v=spf1 ip4:3.122.201.15 ip4:185.138.209.43 ip4:185.138.209.61 ip4:20.61.167.130 ip4:20.61.167.132 include:spf.topdesk.net include:spf.mandrillapp.com include:spf.ess.de.barracudanetworks.com include:spf.email.postex.com include:_spf.zivver.com include:spf.afas.online include:mailswitch.nl include:spf.protection.outlook.com include:spf-westeu.emailsignatures365.com ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=none; rua=mailto:m.wesdijk@klaverblad.nl; ruf=mailto:m.wesdijk@klaverblad.nl; fo=1;policy: none (monitoring only) - DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDp5/mOxVbOT++cnAXocPkBHaoL/FNsBcedH3iGL//sPKhphemad/np3rzLKrGUYRViS0hF4RNFRkO2WFxM6x… - selector2:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDJfFV7c8Na+hyYbRl+yGdVdzQ51QG0el2c10PdNNN79l5O7xGn47Q0OvvywbgmA0De+bZgycS1i7zaPPFdbn…
selectors probed - selector1:
Certificate (current)
DigiCert Global G2 TLS RSA SHA256 2020 CA1
Expires in 231 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Referrer Policy
Header values
- x-frame-options
SAMEORIGIN- permissions-policy
geolocation=(), accelerometer=(), autoplay=(), camera=(), encrypted-media=(), fullscreen=(self "https://www.youtube.com"), gyroscope=(), magnetometer=(), microphone=(), midi=(), payment=(), picture-in-picture=(), usb=()- x-content-type-options
nosniff- content-security-policy
default-src 'self' 'unsafe-inline' optimize.google.com https://plugins.blueconic.net; script-src 'self' 'unsafe-inline' 'unsafe-eval' data: https: wss: https://web.telemetric.dk/ https://linkprotect.cudasvc.com/ https://optimize.google.com/ https://www.google-analytics.com/ https://*.postex.com; child-src 'self'; connect-src 'self' wss: https://*.hotjar.com/api/v2/client/ws https://www.klaverblad.nl/ https://www.google-analytics.com/ https://bat.bing.com/ https://*.doubleclick.net/ https://vc.hotjar.io/ https://in.hotjar.com/ https://insight.bellmetric.net/ https://*.telemetric.dk/ https://klaverblad.blueconic.net/ https://region1.analytics.google.com https://l092.klaverblad.nl https://region1.google-analytics.com/ https://ib.adnxs.com/ https://www.google.com; font-src 'self' data: https://fonts.googleapis.com/ https://fonts.gstatic.com/; frame-src 'self' https://intranet.intern.klaverblad.nl https://webforms.tripolis.com/ https://www.advieskeuze.nl/ https://*.google.com/ https://*.ye- strict-transport-security
max-age=63072000; includeSubDomains