lumc.nl

.nl crawl

First seen 2026-05-13 · Last seen 2026-05-19 · ok HTTP/1.1 200 2566 ms crawled 2026-05-19

NL · 145.88.218.205 · AS1103 SURF B.V.

Reputation 100/100

Classifying

HTML metadata

Title
Leids Universitair Medisch Centrum | LUMC
Description
We werken met elkaar aan een steeds betere gezondheidszorg en gezondheid. Dat is wat ons drijft. Elke dag opnieuw.
Language
nl
Canonical
https://www.lumc.nl/
Translations
  • en
  • nl
Feeds

Open Graph

url
https://www.lumc.nl/
title
Leids Universitair Medisch Centrum | LUMC
description
We werken met elkaar aan een steeds betere gezondheidszorg en gezondheid. Dat is wat ons drijft. Elke dag opnieuw.

Technology

CDN
Cloudflare
CMS
Gatsby
Analytics
  • Google Tag Manager
Cookie consent
  • Cookiebot

Third-party hosts loaded (2)

  • consent.cookiebot.com×1
  • www.googletagmanager.com×1

Social

Registration

Registrar
SURF B.V.
Created
1997-08-25
Updated
2025-07-04
Name servers
  • ns2.surfnet.nl
  • ns1.zurich.surf.net
  • ns1.surfnet.nl

DNS records live

NS
  • ns1.surfnet.nl
  • ns1.zurich.surf.net
  • ns2.surfnet.nl
MX
  • 10 lumc-nl.s-v1.mx.microsoft
TXT
Show 4 TXT records
  • pexip-ms-tenant-domain-verification=44b26bb2-f6cf-45d9-8b34-a2fad6a3a71c
  • have-i-been-pwned-verification=23d8d2c3549401234a2278d1c056cb45
  • pexip-portal-domain-verification=44b26bb2-f6cf-45d9-8b34-a2fad6a3a71c
  • QdhgRNw8+q9gSkFEbke6ysIa8hMmZ4rvrOW8A1gc5VB/uisSphfmtmIU41/hdCPeHNPmplIceHbSJLaZ9/d1Hw==
Verified for
  • Adobe
  • Brevo
  • Dynamics 365
  • Google
  • HARICA
  • Microsoft 365

Email authentication strong

SPF
v=spf1 include:spf.lumc.nl.eu-7wa3oe8s.e1.dspf.app -all
strict (-all)
DMARC
v=DMARC1; p=reject; rua=mailto:7wa3oe8s@ag.eu.dmarcadvisor.com;
policy: reject (enforced)
DKIM
Show 5 DKIM selectors
  • selector1: v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDIsefeA5PhJTZ7eukFxZDUPW8LWhM5m0WZg2vpybmka9ouKzDIeAyhrZcTCQyCHfYMCptidzPKd7HpwHijHA…
  • k2: v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAv2aC2KjGKLOwTweBY5A9RpjsxaBXR9r7OAU6U8/zn92ivImI75naUujWbItRI/QmL1jy5PWGqLwoUA…
  • mail: k=rsa;p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDeMVIzrCa3T14JsNY0IRv5/2V1/v2itlviLQBwXsa7shBD6TrBkswsFUToPyMRWC9tbR/5ey0nRBH0ZVxp+lsmTxid2Y2z…
  • s1: k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAxxBltSH57s95FDRiEBpJEu5YPfH4U5NkvvnHKSkUMCuvkuGLVIxHtceDQOGujR/fKkmMlpk7/yC7pZQ9pB…
  • s2: k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCqpBq6XZDF1N/PmZ9c7+uGt0H+kLtM9YP2qSzdb/kl/xxgCMjO7NsjWF+Kn5U9YmdWvxeLRE9CDNTmHk26rv2shy…
selectors probed

Certificate (current)

GEANT TLS ECC 1
from 2025-08-05 to 2026-08-05
Expires in 77 days

HTTP security headers

Header hygiene 90/100 Checked live page: https://www.lumc.nl/

present
  • strict-transport-security
  • content-security-policy
  • x-frame-options
  • x-content-type-options
  • referrer-policy
  • permissions-policy
  • cross-origin-opener-policy
  • cross-origin-embedder-policy
  • cross-origin-resource-policy
findings
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
Header values
referrer-policy
strict-origin-when-cross-origin
x-frame-options
sameorigin
permissions-policy
accelerometer=(), camera=(), geolocation=(), gyroscope=(), magnetometer=(), microphone=(), payment=(), usb=()
x-content-type-options
nosniff
content-security-policy
default-src 'self' blob: federatie.lumc.nl topdesk.lumc.nl; script-src 'self' 'unsafe-eval' 'unsafe-inline' unpkg.com cdn.jsdelivr.net *.vo.msecnd.net *.vev.page *.vev.design *.cookiebot.com giftforms.nl fundfactory.nl *.visualwebsiteoptimizer.com app.vwo.com blob: *.lumc.nl *.ytimg.com *.gstatic.com *.hotjar.com dl.episerver.net *.google.com *.googletagmanager.com www.google-analytics.com *.mailplus.nl *.azure.com cdnjs.cloudflare.com code.jquery.com maxcdn.bootstrapcdn.com snap.licdn.com connect.facebook.net; style-src 'self' 'unsafe-inline' *.lumc.nl cdn.jsdelivr.net *.visualwebsiteoptimizer.com giftforms.nl app.vwo.com s3.amazonaws.com *.cloudflare.com *.googletagmanager.com tagmanager.google.com fonts.googleapis.com dl.episerver.net static.mailplus.nl; img-src 'self' *.ytimg.com blob: data: *.lumc.nl *.visualwebsiteoptimizer.com *.vev.design *.cookiebot.com giftforms.nl fundfactory.nl chart.googleapis.com wingify-assets.s3.amazonaws.com app.vwo.com *.gstatic.com *.hotjar.com www.g
strict-transport-security
max-age=31536000; includeSubDomains
cross-origin-opener-policy
same-origin
cross-origin-embedder-policy
unsafe-none
cross-origin-resource-policy
same-site

Links to (4)

Linked from (4)