mrfillet.nl

.nl crawl

First seen 2026-06-04 · Last seen 2026-06-05 · ok HTTP/1.1 200 742 ms crawled 2026-06-05

NL · 93.186.186.36 · AS20559 Fundaments B.V.

Reputation 94/100 dmarc monitor-only

Classifying

HTML metadata

Title
Verse Kipfilet €9,99 p/kg – Vandaag Geleverd & Gratis - mr. Fillet
Description
Verse Nederlandse kip direct van onze slachterij, met de hand gefileerd. €9,99 per kilo, altijd gratis bezorgd. Voor 10:00 besteld = vanavond in huis.
Language
nl
Canonical
https://www.mrfillet.nl

Open Graph

url
https://www.mrfillet.nl
title
Verse Kipfilet €9,99 p/kg – Vandaag Geleverd & Gratis
description
Verse Nederlandse kip direct van onze slachterij, met de hand gefileerd. €9,99 per kilo, altijd gratis bezorgd. Voor 10:00 besteld = vanavond in huis.

Technology

Server
nginx
Analytics
  • Google Tag Manager

Third-party hosts loaded (1)

  • www.googletagmanager.com×1

Social

Contact

Address
Dieselweg 16, 3752 LB, Bunschoten-Spakenburg, Utrecht, NL

DNS records live

NS
  • docks05.rzone.de
  • shades09.rzone.de
MX
  • 10 mrfillet-nl.mail.protection.outlook.com
  • 20 em16554.mrfillet.nl
Verified for
  • Apple
  • Google
  • Microsoft 365
  • OpenAI

Email authentication partial

SPF
v=spf1 a include:spf.office-box.nl ip6:2a01:7c8:aab5:352::1/48 ip6:2a01:7c8:aab5:352::1/48 include:spf.afas.online include:_spf.google.com include:spf.ccvshop.eu include:spf.protection.outlook.com -all
strict (-all)
DMARC
v=DMARC1; p=none
policy: none (monitoring only)
DKIM
  • selector1: v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEArqZGZuXFzdYNo4D0bIb8Scrx5oZ2/pXYBYbWUsrT2X3mlQEfK1jEHuKU1rvwsm1exOaCu4BccTg/bs…
  • selector2: v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA+4kz8TlCvKdppaySERnjb63sIZtD7okTtFF/8fLVsGlXUvhU9OMPlwFdi8UrZy+8TSr/2lgm7bMIE2…
selectors probed

Certificate (current)

R12
from 2026-04-28 to 2026-07-27
Expires in 52 days

HTTP security headers

Header hygiene 70/100 Checked live page: https://www.mrfillet.nl/

present
  • content-security-policy
  • x-frame-options
  • x-content-type-options
  • referrer-policy
  • permissions-policy
findings
  • missing HSTS
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
Header values
referrer-policy
strict-origin-when-cross-origin
x-frame-options
DENY
permissions-policy
camera=(), usb=(), microphone=(), midi=()
x-content-type-options
nosniff
content-security-policy
default-src 'self' https:; object-src 'none'; img-src 'self' data: https:; script-src 'self' 'unsafe-eval' 'unsafe-inline' https:; style-src 'self' 'unsafe-eval' 'unsafe-inline' *.googleapis.com; frame-ancestors *.webnl.nl; font-src 'self' *.googleapis.com *.gstatic.com; frame-src https:; worker-src blob:;

Links to (3)

Linked from (1)