onderwijsportalen.nl

.nl crawl

First seen 2026-06-04 · Last seen 2026-06-04 · ok HTTP/1.1 200 727 ms crawled 2026-06-04

NL · 89.41.170.135 · AS20857 Signet B.V.

Reputation 92/100 no dmarc policy

Classifying

HTML metadata

Title
Onderwijs Portaal
Language
nl

Technology

Server
nginx
Stack
PHP

DNS records live

NS
  • ns0.transip.net
  • ns1.transip.nl
  • ns2.transip.eu
MX
  • 10 inbound-smtp.eu-west-1.amazonaws.com
TXT
  • 0 issue "letsencrypt.org"
Verified for
  • Google

Email authentication weak

SPF
not published
DMARC
not published
DKIM
no key found at common selectors

Certificate (current)

R13
from 2026-04-04 to 2026-07-03
Expires in 28 days

HTTP security headers

Header hygiene 65/100 Checked live page: https://onderwijsportalen.nl/home

present
  • strict-transport-security
  • content-security-policy
  • permissions-policy
  • cross-origin-opener-policy
  • cross-origin-embedder-policy
findings
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
  • missing frame protection
  • missing content type protection
  • missing Referrer Policy
Header values
permissions-policy
accelerometer=*, autoplay=*, fullscreen=*, picture-in-picture=*, web-share=*
content-security-policy
default-src * 'unsafe-inline' 'unsafe-hashes' 'unsafe-eval'; img-src 'self' https://cdn.onderwijsportalen.nl https://api.onderwijsportalen.nl https://messenger.onderwijsportalen.nl https://content.jwplatform.com https://assets-jpcust.jwpsrv.com https://prd.jwpltx.com https://i.ytimg.com https: data:; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://cdn.onderwijsportalen.nl https://forms.onderwijsportalen.nl https://api.onderwijsportalen.nl https://bulkpdf.onderwijsportalen.nl https://messenger.onderwijsportalen.nl https://cdn.jwplayer.com https://content.jwplatform.com https://ssl.p.jwpcdn.com https://mozilla.github.io; media-src 'self' https://videos-cloudfront.jwpsrv.com https://content.jwplatform.com blob:; worker-src 'self' blob:; frame-src 'self' blob: https://mozilla.github.io https://view.officeapps.live.com https://www.youtube-nocookie.com;
strict-transport-security
max-age=63072000; includeSubDomains; preload
cross-origin-opener-policy
same-origin-allow-popups
cross-origin-embedder-policy
unsafe-none

Linked from (2)