nu.nl
HTML metadata
Technology
- Analytics
-
- Google Tag Manager
Third-party hosts loaded (11)
- advertising-cdn.dpgmedia.cloud×7
- login-static.dpgmedia.net×3
- www.googletagmanager.com×3
- dev.visualwebsiteoptimizer.com×2
- myprivacy-static.dpgmedia.net×2
- myprivacy.dpgmedia.net×2
- static.pexi.nl×2
- widgets.pexi.nl×2
- applets.ebxcdn.com×1
- cdn.optoutadvertising.com×1
- static.qmusic.be×1
Social
Contact
- Phone
DNS records live
- NS
-
- eur2.akam.net
- eur5.akam.net
- eur6.akam.net
- ns1-125.akam.net
- ns1-25.akam.net
- usc2.akam.net
- use2.akam.net
- use5.akam.net
- MX
-
- 1 aspmx.l.google.com
- 10 alt3.aspmx.l.google.com
- 10 alt4.aspmx.l.google.com
- 5 alt1.aspmx.l.google.com
- 5 alt2.aspmx.l.google.com
- TXT
-
Show 7 TXT records
44H7wFK0U1bPombNvcSDEEeuh4tt0XfAGrMWp9Rud0zNncmKY4X9Xy6/ZIdK76RU8kFePsDZNiazxafW6c2Kfg==j9fp8pgv04h1sj684g6mbudvbjfacebook-domain-verification=y39uvlb8me78wtka5eak2twy6ws9kbMS=ms74543461klaviyo-site-verification=TSJiF9google-site-verification=5a_rbsm2U7Ui-D8iQWKPPINvNczda7puIqliz_4eVhEgoogle-site-verification=FK-oosEnGeJyF9X8h9_n7Ck1qBaTFlRepZlStiYyiq8
Email authentication strong
- SPF
-
v=spf1 include:_spf.dpgmmservices.nl include:spf.protection.outlook.com include:_spf.google.com include:mail.zendesk.com -allstrict (-all) - DMARC
-
v=DMARC1; p=quarantine; rua=mailto:zurbc63x@ag.eu.dmarcadvisor.com; ruf=mailto:zurbc63x@fr.eu.dmarcadvisor.com; fo=1; pct=100policy: quarantine - DKIM
-
- google:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQClVhAC1/7put4iKv51+ffoPSdxB0EUcbnCAhtXHh3Jmcod8gsNHY+p5lcZYhbFUTKCqPzjuXz3YujhMvfE55… - s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEApK4KCE8J7hregabUXm+YODd3bpDceyRLeVKvIvLwf7KoQj4jDx0Leu0YxuiL1ZuyFnJSo/GyXRES4cqsao… - s2:
k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDUPnptPNpJXROFfRNIks0Tqt3nt98cjOqUTXB/GRo+soEFSe1f/Cfi3EtnsawklDuH5nYZ3HOPCuhKC1B3664h0e…
selectors probed - google:
Certificate (current)
DigiCert Global G3 TLS ECC SHA384 2020 CA1
Expires in 139 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-content-type-options
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- missing frame protection
- missing Referrer Policy
Header values
- permissions-policy
ch-ua-model=*,ch-ua-platform-version=*- x-content-type-options
nosniff- content-security-policy
child-src data: https: blob:; default-src data: 'unsafe-inline' 'unsafe-eval' https:; upgrade-insecure-requests; connect-src https: wss: blob:; font-src data: https:; style-src data: 'unsafe-inline' https: blob:; style-src-elem data: 'unsafe-inline' https: blob:; media-src data: https: blob:; img-src data: https: blob:; script-src data: 'unsafe-inline' 'unsafe-eval' https: blob:; object-src https:; form-action https:;- strict-transport-security
max-age=31536000; includeSubDomains
Links to (13)
- apple.com×1
- awin1.com×1
- bsky.app×1
- dpgmedia.nl×1
- dpgmediagroup.com×1
- facebook.com×1
- google.com×1
- instagram.com×1
- nuadverteren.nl×1
- reclamefolder.nl×1
- tiktok.com×1
- x.com×1
- youtube.com×1