ovpay.nl
HTML metadata
Technology
- CDN
- Azure Front Door
- CMS
- Next.js
- Cookie consent
-
- Cookiebot
Third-party hosts loaded (4)
- applepay.cdn-apple.com×1
- consent.cookiebot.com×1
- deploy.mopinion.com×1
- dok.js-cdn.dynatrace.com×1
DNS records live
- NS
-
- a1-167.akam.net
- a10-67.akam.net
- a12-65.akam.net
- a26-64.akam.net
- a3-64.akam.net
- a5-67.akam.net
- MX
-
- 1 ovpay-nl.mail.protection.outlook.com
- TXT
-
_gruphistkijocnp1oxbl6wsgpfpxo1p
- Verified for
-
- Microsoft 365
Email authentication partial
- SPF
-
v=spf1 ip4:213.138.140.195 include:spf.protection.outlook.com include:spf.flowmailer.net ~allsoftfail (~all) - DMARC
-
v=DMARC1;p=none;sp=quarantine;pct=100;rua=mailto:dmarc@inbound.flowmailer.net,mailto:d0dd6374d2@rua.easydmarc.eu;ruf=mailto:dmarc@inbound.flowmailer.net,mailto:d0dd6374d2@ruf.easydmarc.eu;fo=1;aspf=r;adkim=rpolicy: none (monitoring only) · sp=quarantine - DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAy/OzIwyTk5ehpqLX37H22HRTlI0vZZpn1+qc+esH6Vq2wUrVIK+4fLNEp2wgr+KcEzJW5IoZpXYKTw… - s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAyoMbMSwDDOG3jlHvXLOAffOVq1bMfsKPaEzTzKkPwjsnMfQEW3sy5NeOKEcPxSszmkDatcmcqEcj+9doSc… - s2:
k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDJmftbWngL2kySkJxzYRKVsyH1m1DdlGXbzj63FrV/N3bHLvT+NeWifAMlR47WpWp2CbybtDE2IjUTWXHZgcwh1a…
selectors probed - selector1:
Certificate (current)
DigiCert Global G2 TLS RSA SHA256 2020 CA1
Expires in 243 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-content-type-options
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing frame protection
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-content-type-options
nosniff- content-security-policy
default-src 'self'; font-src https://fonts.gstatic.com https://gstatic.mopinion.com https://applepay.cdn-apple.com https://*.egain.cloud data: 'self'; style-src https://fonts.googleapis.com https://fonts.mopinion.com https://*.egain.cloud https://*.ovpay.nl https://*.egain.cloud 'self' 'unsafe-inline'; script-src 'self' https://*.cookiebot.com https://dok.js-cdn.dynatrace.com https://*.mopinion.com https://*.egain.cloud https://www.facebook.com https://*.facebook.com https://facebook.com https://connect.facebook.net 'unsafe-inline' 'unsafe-eval' https://applepay.cdn-apple.com; connect-src 'self' https://*.ovpay.nl https://api.identity.ovpay.app https://*.in.applicationinsights.azure.com https://stdisruptionsprod.blob.core.windows.net https://js.monitor.azure.com https://*.cookiebot.com https://*.dynatrace.com https://*.mopinion.com https://*.egain.cloud https://www.facebook.com https://*.facebook.com https://facebook.com https://connect.facebook.net https://smp-paymentservices.apple.co- strict-transport-security
max-age=31536000