oostnl.nl
HTML metadata
Technology
- Server
- nginx
- CMS
- Next.js
- JS framework
- Next.js
Social
Contact
- Phone
DNS records live
- NS
-
- ns1.sectigoweb.com
- ns2.sectigoweb.com
- ns3.sectigoweb.com
- ns4.sectigoweb.com
- MX
-
- 40 d341266.a.ess.de.barracudanetworks.com
- 50 d341266.b.ess.de.barracudanetworks.com
- TXT
-
0ed1fe018ac7a532cfe537436db23a6f7ccd8944c3
- Verified for
-
- Dynamics 365
- Meta
- Microsoft 365
- OpenAI
Email authentication partial
- SPF
-
v=spf1 include:spf.ess.de.barracudanetworks.com include:eur.pb-dynmktge.com include:de._netblocks.mimecast.com ip4:64.225.67.133/32 ip4:194.104.108.22 ip4:185.31.244.236 ip4:217.114.99.187 ip4:217.114.99.177 ip4:85.17.68.46 ip4:5.226.149.176 ip4:217.114.99.37 a:mailrelay.nubium.nl include:spf.protection.outlook.com include:_spf.elonisas.nl include:spf.virtu.nl include:spf.afas.online include:_spf.benp.nl include:amazonses.com -allstrict (-all) - DMARC
-
v=DMARC1; p=none; sp=none; rua=mailto:watchdog2@watchdog.kevlarr.io; adkim=r; aspf=r;policy: none (monitoring only) · sp=none - DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCW9/eX0QmUC8K/urzSli0r/s6nYEXqxHSg5m5bFl6YOS8VXu/tjiywjYMR2+1L15ulWDh8/t5q7M1DeYuA1G…
selectors probed - selector1:
Certificate (current)
Amazon RSA 2048 M04
Expires in 198 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing frame protection
Header values
- referrer-policy
no-referrer-when-downgrade- permissions-policy
geolocation=(),midi=(),sync-xhr=(),microphone=(),camera=(),magnetometer=(),gyroscope=(),fullscreen=(self),payment=()- x-content-type-options
nosniff- content-security-policy
object-src 'none'; default-src * data: 'self' blob:; frame-ancestors 'self' *.oostnl.nl *.oostnl.com *.oostnl-dev.nl app.useberry.com; script-src 'unsafe-eval' 'unsafe-inline' 'self' blob: *.oostnl.nl *.oostnl.com *.oostnl-dev.nl *.youtube.com *.vimeo.com *.userback.io *.gstatic.com *.algolia.net *.googletagmanager.com *.cookiebot.com *.landbot.io *.azureedge.net *.useberry.com; style-src 'self' 'unsafe-inline' *.googleapis.com *.gstatic.com *.oostnl.nl *.oostnl.com *.oostnl-dev.nl *.cookiebot.com *.userback.io *.googletagmanager.com *.landbot.io *.azureedge.net;- strict-transport-security
max-age=31536000; includeSubdomains;