mijnpensioenoverzicht.nl
HTML metadata
Technology
- CDN
- Azure Front Door
- CMS
- Next.js
DNS records live
- NS
-
- ns1.openprovider.nl
- ns2.openprovider.be
- ns3.openprovider.eu
- MX
-
- 0 gw.tdax.nl
- TXT
-
Show 4 TXT records
1hm2zt070vy0xdfhj72ftsxtccz0hh4tibmmf49vij5h3mkliehgkjr1ob658057i0gcpii7qfgpnb6lv3r2s8en1p
Email authentication strong
- SPF
-
v=spf1 include:interleave.nl include:spf.messagelabs.com mx -allstrict (-all) - DMARC
-
v=DMARC1; p=quarantine; fo=1; adkim=r; aspf=r; pct=100; sp=quarantinepolicy: quarantine · sp=quarantine - DKIM
-
- selector2:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQC8qg9ZselhZ5YJpVBc6QHwco6hnS6ouoA81rDlONB6vcpu+gK3dNKF8AKAXZROSA+8IioG9wi/p/PnasHJ2u…
selectors probed - selector2:
Certificate (current)
GeoTrust TLS RSA CA G1
Expires in 101 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Permissions Policy
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src 'self' https://www.mijnpensioenoverzicht.nl 'nonce-uFIqLJ7vx2qCALzC'; media-src 'self' https://www.mijnpensioenoverzicht.nl 'nonce-uFIqLJ7vx2qCALzC' https://*.storyblok.com; script-src 'self' https://www.mijnpensioenoverzicht.nl 'nonce-uFIqLJ7vx2qCALzC' https://scripts.clarity.ms https://www.clarity.ms https://*.mopinion.com http://*.mopinion.com 'unsafe-inline' ; script-src-elem 'self' https://www.mijnpensioenoverzicht.nl 'nonce-uFIqLJ7vx2qCALzC' https://scripts.clarity.ms https://www.clarity.ms https://*.mopinion.com http://*.mopinion.com 'unsafe-inline'; style-src 'self' https://www.mijnpensioenoverzicht.nl 'unsafe-inline'; img-src 'self' https://www.mijnpensioenoverzicht.nl https://*.storyblok.com; connect-src 'self' https://www.mijnpensioenoverzicht.nl https://www.mijnpensioenoverzicht.nl https://login.microsoftonline.com https://*.azurewebsites.net https://*.clarity.ms https://js.monitor.azure.com/ https://westeurope-5.in.applicationinsights.azure.com https://*.mopini- strict-transport-security
max-age=63072000; includeSubDomains; preload