lachjekrom.com
HTML metadata
Technology
- Server
- nginx
- Ads
-
- Google AdSense
- Fonts
-
- Google Fonts
Third-party hosts loaded (3)
- fonts.googleapis.com×2
- fonts.gstatic.com×1
- pagead2.googlesyndication.com×1
Social
Registration
- Registrar
- Combell NV
- Created
- 2001-12-12
- Expires
- 2026-12-12 206 days left
- Updated
- 2025-12-13
- Name servers
-
- ns1.easyhost.be
- ns2.easyhost.be
- ns3.easyhost.be
DNS records live
- NS
-
- ns1.easyhost.be
- ns2.easyhost.be
- ns3.easyhost.be
- MX
-
- 10 mx.mailprotect.be
- 50 mx.backup.mailprotect.be
- TXT
-
google-site-verification=E8cpUSSKvFmSQTzvDiQX4j_TkoVLX_jto4lhFq89VpAdns+mail-grant:z4a3xkujaayq/cx6sahy2svjjda=
Email authentication weak
- SPF
-
v=spf1 mx a include:_spf.relay.mailprotect.be -allstrict (-all) - DMARC
- not published
- DKIM
- no key found at common selectors
Certificate (current)
R13
Expires in 43 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- short HSTS max-age
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
sameorigin- permissions-policy
accelerometer=(), camera=(), microphone=(), geolocation=(), usb=(), fullscreen=(self);report-to=default- x-content-type-options
nosniff- content-security-policy
default-src 'self'; font-src 'self' fonts.gstatic.com; style-src 'self' 'unsafe-inline' fonts.googleapis.com;img-src 'self' blob: data: *.gstatic.com *.imgur.com *.youtube.com *.ytimg.com *.vimeocdn.com *.dailymotion.com *.dmcdn.net *.pinterest.com *.googlesyndication.com *.adtrafficquality.google;script-src 'self' 'nonce-hdcoreadsrandomchars' 'unsafe-eval' cdn.ampproject.org *.googleapis.com *.pinterest.com www.youtube.com *.googlesyndication.com *.google.com *.adtrafficquality.google https://challenges.cloudflare.com; connect-src 'self' csi.gstatic.com *.google.com *.googlesyndication.com *.adtrafficquality.google;frame-src 'self' *.youtube-nocookie.com *.dailymotion.com *.pinterest.com *.vimeo.com *.googlesyndication.com googleads.g.doubleclick.net *.google.com *.adtrafficquality.google https://challenges.cloudflare.com; object-src 'none';base-uri 'self';form-action 'self';report-to default;report-uri https://api.hdcore.be/api/csp-reports/post/lachjekrom- strict-transport-security
max-age=86400