operaballet.nl
HTML metadata
Technology
- Server
- nginx
- CMS
- Drupal
- Analytics
-
- Google Tag Manager
Third-party hosts loaded (1)
- www.googletagmanager.com×1
Social
Contact
- Phone
Registration
- Registrar
- Accenture B.V.
- Created
- 2012-07-18
- Updated
- 2021-07-19
- Name servers
-
- ns4.sentia.nl
- ns7.sentia.net
- ns5.sentia.nl
- ns6.sentia.net
DNS records live
- NS
-
- ns4.sentia.nl
- ns5.sentia.nl
- ns6.sentia.net
- ns7.sentia.net
- MX
-
- 0 operaballet-nl.mail.protection.outlook.com
Email authentication strong
- SPF
- not published
- DMARC
-
v=DMARC1; p=quarantine; rua=mailto:dmarc_agg@vali.email; fo=1; adkim=r; aspf=r; pct=100; rf=afrf; ri=86400; sp=quarantinepolicy: quarantine · sp=quarantine - DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCeLWDinVfsz/GlLXSS2mTNMCSnYTnNgX/w9E+xoGeFaSGjesER28q5oElM9gsDuAw+idoPIXxDDYhkM1zrp/…
selectors probed - selector1:
Certificate (current)
Sectigo Public Server Authentication CA OV R36
Expires in 279 days
HTTP security headers
- present
-
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- missing HSTS
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Permissions Policy
Header values
- referrer-policy
no-referrer-when-downgrade- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://cdnjs.cloudflare.com https://static.cloudflareinsights.com https://consentcdn.cookiebot.com https://consent.cookiebot.com https://unpkg.com https://cdn.jsdelivr.net https://www.googletagmanager.com *.google-analytics.com https://*.google.com https://ssl.google-analytics.com https://www.googleadservices.com https://*.doubleclick.net dev.visualwebsiteoptimizer.com *.leadfamly.com https://*.pinterest.com https://connect.facebook.net https://*.adform.net https://*.adnxs.com *.hotjar.com *.hotjar.io *.pinimg.com *.mailplus.nl https://*.gstatic.com https://www.youtube.com/iframe_api https://www.youtube.com/s/player/ https://pipeline.operaballet.nl https://blokks.co https://themes.blokks.cloud https://*.clarity.ms https://widget.slinger.to https://*.omniconvert.com https://bat.bing.com; style-src 'self' 'unsafe-inline' https://cdnjs.cloudflare.com cdn.jsdelivr.net https://tagmanager.google.com https://fonts.googleapi