nationale-loterij.be
HTML metadata
Technology
- CDN
- Azure Front Door
- Fonts
-
- Adobe Fonts
Third-party hosts loaded (6)
- assets.adobedtm.com×2
- use.typekit.net×2
- p.typekit.net×1
- rum.hlx.page×1
- www.loterie-nationale.be×1
- www.nationallotterie.be×1
Social
Contact
- Address
- Belliardstraat 25-33, 1040, Brussel, Brussel, België
DNS records live
- NS
-
- ns1.combell.eu
- ns3.combell.net
- ns4.combell.net
- MX
-
- 0 nationaleloterij-be02c.mail.protection.outlook.com
- TXT
-
Show 8 TXT records
DJgVDybwtFBs/qV/5sAS3CGWB73GO0clHNq3+Z/AVQV4pG+XnTlss8haGowgcNU4ze+MryqnyoBqP3rEQHBdxA==QuoVadis=a58a13ed-40b9-4c82-b2d4-1fe8ff7e3d139DHJC6ip5v7VSqymSq/22cChfx0VcdWbRunF4vj8No0=QuoVadis=8a44895a-3816-4f02-825c-c60d6ee7967csg/zFcq1woLg7J8T1s9n0KWZt9gkDGz4w9c9yIiJmns=QuoVadis=51b44f4c-7d19-48f0-bcc0-04b6f34d8f0fjOv/RhmH/97coLrWB/Rg8E74IRUDXbY/Uj3Kl0V0inHlJslzUcta8f2MfGPKyhWJ2vZlV6iX811P40JGhR0NOw==MS=7B957DAD063E250B28EB63D820AC06C1B6549E79
- Verified for
-
- Adobe
- GlobalSign
- Google Workspace
- Meta
- Microsoft 365
Email authentication partial
- SPF
-
v=spf1 a mx a:mail.twikey.com ip4:91.183.130.192/27 include:spf.protection.outlook.com include:carerix.net include:spf.mandrillapp.com -allstrict (-all) - DMARC
-
v=DMARC1; p=none; rua=mailto:dmarc.report.agg@nationale-loterij.be,mailto:dmarc_agg@vali.email; sp=none;policy: none (monitoring only) · sp=none - DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCs1dk0PqhXmhqkJ58GRwmU0oJbTXQqC25vTdNC3+ZfaNF2lf3LeQnFkZTQ+wkp/QN6y3gLXqx7aQU+wUP5Nt… - s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA3hSc4OzIBE30bDCHjf8eDQjtefRY0OtCPEmS5D2uM3+yILf2MQ3nr9AJJMqmESOXTPtPT45MVdZz60Tqgw… - s2:
k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDB/BuuTh1UIB/Gf2Q674HGFIfUGVr0TksnCQnv2gRgheskTrN4TVojI+t2wxWQSp4GMJW+AH8dJZzxQSFonasWeI…
selectors probed - selector1:
Certificate (current)
E8
Expires in 82 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
no-referrer-when-downgrade- x-frame-options
SAMEORIGIN- permissions-policy
accelerometer=(), ambient-light-sensor=(), autoplay=*, camera=(), display-capture=(), encrypted-media=(), fullscreen=*, geolocation=*, gyroscope=(), magnetometer=(), midi=(), payment=(), picture-in-picture=(), speaker=*, usb=(), web-share=*, xr-spatial-tracking=()- x-content-type-options
nosniff- content-security-policy
default-src 'self' https: 'unsafe-eval' 'unsafe-inline'; object-src 'self' blob:; img-src 'self' data: https:; media-src 'self' data: https: blob:; font-src 'self' data: https:; frame-src 'self' https: blob: data: tel:; frame-ancestors 'self' https://loterienationalenationale.qualifioapp.com/ https://experience.adobe.com/ https://aem-nl.prd.natlot.be https://aem-fr.prd.natlot.be https://aem-de.prd.natlot.be https://lonet.lonalo.be/; worker-src 'self' 'unsafe-inline' * blob:; connect-src 'self' https: https://sdk.privacy-center.org/ https://api.privacy-center.org/ wss://*.hotjar.com wss://webmessaging.mypurecloud.de;- strict-transport-security
max-age=31536000; includeSubDomains; preload