mrphan-restaurant.nl
HTML metadata
Technology
- Server
- nginx
Third-party hosts loaded (2)
- debestelapp.nl×7
- maps.google.com×1
Social
Contact
- Phone
- Address
- Stadhuisstraat 6, 1315HA, Almere, Nederland
Registration
- Registrar
- OVH
- Created
- 2025-04-03
- Updated
- 2026-03-23
- Name servers
-
- ns2.bluebirdmedia.nl
- ns1.bluebirdmedia.nl
DNS records live
- NS
-
- ns1.bluebirdmedia.nl
- ns2.bluebirdmedia.nl
- MX
-
- 10 mail.mrphan-restaurant.nl
- Verified for
-
Email authentication strong
- SPF
-
v=spf1 +a +mx +a:plesk.bluebirdmedia.nl -allstrict (-all) - DMARC
-
v=DMARC1; p=quarantine; adkim=s; aspf=spolicy: quarantine - DKIM
- no key found at common selectors
Certificate (current)
R13
Expires in 46 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy-report-only
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- cross-origin-opener-policy
- cross-origin-embedder-policy
- cross-origin-resource-policy
- findings
-
- missing Content Security Policy
- weak frame protection
- weak content type protection
Header values
- referrer-policy
same-origin- x-frame-options
deny, SAMEORIGIN- permissions-policy
accelerometer=(), ambient-light-sensor=(), autoplay=(), battery=(), camera=(), clipboard-read=(), clipboard-write=(self), display-capture=(), document-domain=(), encrypted-media=(), execution-while-not-rendered=(), execution-while-out-of-viewport=(), fullscreen=(), gamepad=(), geolocation=(), gyroscope=(), hid=(), identity-credentials-get=(), idle-detection=(), local-fonts=(), magnetometer=(), microphone=(), midi=(), otp-credentials=(), payment=(), picture-in-picture=(), publickey-credentials-create=(), publickey-credentials-get=(), screen-wake-lock=(), serial=(), speaker-selection=(), storage-access=(), usb=(), web-share=(self), xr-spatial-tracking=()- x-content-type-options
nosniff, nosniff- strict-transport-security
max-age=63072000; includeSubDomains; preload- cross-origin-opener-policy
same-origin- cross-origin-embedder-policy
same-origin- cross-origin-resource-policy
same-origin- content-security-policy-report-only
base-uri 'self'; child-src 'self' https://www.quandoo.nl/ https://js.stripe.com/; connect-src 'self' https://plausible.debestelapp.nl/ https://sentry.debestelapp.nl/ https://9110-api.quandoo.com/ https://booking-widget.quandoo.com/ https://api.stripe.com/ https://m.stripe.com/ wss://ws.debestelapp.nl:443; default-src 'none'; font-src 'self' data: https://fonts.bunny.net/; form-action 'self'; frame-ancestors 'none'; frame-src 'self' https://www.quandoo.nl/ https://maps.google.com/ https://www.google.com/ https://js.stripe.com/ https://www.youtube.com/ https://www.youtube-nocookie.com/ https://player.vimeo.com/; img-src 'self' data: blob: https://debestelapp.nl/ https://*.tile.openstreetmap.org/; manifest-src 'self'; media-src 'self'; object-src 'none'; script-src 'self' 'nonce-YsfUIO6VE5uPd9PS7VV7Vv36JnLLsvy032UqNrfI' https://plausible.debestelapp.nl https://js.stripe.com/ https://booking-widget.quandoo.com/ https://9110-api.quandoo.com/; style-src 'self' 'unsafe-inline' https://fonts.b