nbc.nl
HTML metadata
Technology
- jQuery
- 3.6.0
- Analytics
-
- Google Tag Manager
- Fonts
-
- Google Fonts
Third-party hosts loaded (5)
- static.mailplus.nl×4
- fonts.googleapis.com×2
- fonts.gstatic.com×1
- m12.mailplus.nl×1
- www.googletagmanager.com×1
Social
DNS records live
- NS
-
- ns1.argewebhosting.eu
- ns2.argewebhosting.com
- ns3.argewebhosting.nl
- MX
-
- 10 nbc-nl.mail.eo.outlook.com
- Verified for
-
- Meta
Email authentication partial
- SPF
-
v=spf1 include:spf.protection.outlook.com a:maisbrood.nbc.nl include:mailplus.nl include:_spf.paytsoftware.com a:vpn.nbc.nl a:vpn-backup.nbc.nl include:spf.EU.exclaimer.net -allstrict (-all) - DMARC
-
v=DMARC1; p=none;policy: none (monitoring only) - DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAtMn19J88LybCNfHpWsvSSqcyxjQ9lyaeYunvRJgx1FlmD16LW5cVWAgsDq5VUQdKa7hTldOEg317c6… - selector2:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA94vC6nirjnm0dvf5r4XSNIZuTmJeFVLEyKQk/0yQE94ZYAzVwCH6DvP1L+OxDeN+1OfIPPEFNddGB6…
selectors probed - selector1:
Certificate (current)
Sectigo RSA Domain Validation Secure Server CA
Expires in 24 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Permissions Policy
Header values
- referrer-policy
Origin-when-cross-origin- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
script-src *.cookiebot.com *.ggpht.com *.google.com *.google-analytics.com *.googletagmanager.com *.googleusercontent.com *.gstatic.com *.mailplus.nl accp.foodbase.nl accp.nbc.nl connect.facebook.net facebook.net https://googleads.g.doubleclick.net/pagead/ 'self' snap.licdn.com 'unsafe-eval' 'unsafe-inline' www.google-analytics.com www.googletagmanager.com;img-src *.cookiebot.com *.google.com *.googleapis.com *.googletagmanager.com *.googleusercontent.com data: https://googleads.g.doubleclick.net/pagead/ https://www.google.nl/pagead/ px.ads.linkedin.com 'self' www.facebook.com;frame-src *.cookiebot.com *.google.com accp.foodbase.nl accp.nbc.nl https://www.facebook.com/ https://www.googletagmanager.com www.youtube.com www.youtube-nocookie.com;connect-src *.cookiebot.com *.google.com *.google-analytics.com *.googleapis.com blob: data: px.ads.linkedin.com 'self' ws://localhost:* wss://localhost:* www.facebook.com;default-src *.google.com;style-src *.mailplus.nl https://fonts.googleapis.co- strict-transport-security
max-age=31536000