maasheggenkids.nl

.nl crawl

First seen 2026-05-31 · Last seen 2026-06-01 · ok HTTP/1.1 200 344 ms crawled 2026-06-01

NL · 89.31.98.42 · AS35470 Signet B.V.

Reputation 92/100 no dmarc policy

Classifying

HTML metadata

Title
Altijd iets leuks in de Maasheggen - Maasheggenkids
Description
In de bijzondere Maasheggen is van alles te ontdekken en beleven!Hier op MaasheggenKids.nl vind je allerlei leuke ideeën, activiteiten en routes om de …
Language
nl
Canonical
https://www.maasheggenkids.nl/home/

Open Graph

url
https://www.maasheggenkids.nl/home/
title
Altijd iets leuks in de Maasheggen
locale
nl_NL
site name
Maasheggenkids
description
In de bijzondere Maasheggen is van alles te ontdekken en beleven!Hier op MaasheggenKids.nl vind je allerlei leuke ideeën, activiteiten en routes om de …

Technology

Server
nginx
Analytics
  • Google Tag Manager
Fonts
  • Google Fonts

Third-party hosts loaded (3)

  • fonts.googleapis.com×3
  • fonts.gstatic.com×1
  • www.googletagmanager.com×1

Social

DNS records live

NS
  • ns1.cybox.nl
  • ns2.cybox.eu
MX
  • 0
TXT
  • v=DMARC1; p=reject;

Email authentication weak

SPF
v=spf1 -all
strict (-all)
DMARC
not published
DKIM
Show 12 DKIM selectors
  • default: v=DKIM1; p=
  • google: v=DKIM1; p=
  • selector1: v=DKIM1; p=
  • selector2: v=DKIM1; p=
  • k1: v=DKIM1; p=
  • k2: v=DKIM1; p=
  • mail: v=DKIM1; p=
  • dkim: v=DKIM1; p=
  • s1: v=DKIM1; p=
  • s2: v=DKIM1; p=
  • mxvault: v=DKIM1; p=
  • smtpapi: v=DKIM1; p=
selectors probed

Certificate (current)

R13
from 2026-05-26 to 2026-08-24
Expires in 83 days

HTTP security headers

Header hygiene 75/100 Checked live page: https://www.maasheggenkids.nl/

present
  • strict-transport-security
  • content-security-policy
  • x-content-type-options
  • referrer-policy
findings
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
  • missing frame protection
  • missing Permissions Policy
Header values
referrer-policy
strict-origin-when-cross-origin
x-content-type-options
nosniff
content-security-policy
default-src 'self'; style-src 'self' 'unsafe-inline' fonts.googleapis.com *.typekit.net; script-src 'self' *.googletagmanager.com *.google-analytics.com 'unsafe-eval' https://*.googleapis.com *.typekit.net 'nonce-DlvevTY0s9LDEEBxBTYSYw=='; img-src 'self' data: i.ytimg.com i.vimeocdn.com *.googletagmanager.com *.google-analytics.com https://*.googleapis.com https://*.gstatic.com *.google.com *.googleusercontent.com *.typekit.net; frame-src 'self' www.youtube.com player.vimeo.com *.google.com; connect-src 'self' *.analytics.google.com *.googletagmanager.com *.google-analytics.com https://stats.g.doubleclick.net https://*.googleapis.com *.google.com https://*.gstatic.com data: blob: performance.typekit.net; base-uri 'self'; font-src 'self' fonts.gstatic.com *.typekit.net; frame-ancestors 'self';
strict-transport-security
max-age=63072000; includeSubDomains

Links to (5)