recycleapp.be
HTML metadata
Technology
- Server
- webserver
- CMS
- Gatsby
Third-party hosts loaded (1)
- js-cdn.dynatrace.com×1
DNS records live
- NS
-
- ns1.combell.eu
- ns3.combell.net
- ns4.combell.net
- MX
-
- 10 mx.mailprotect.be
- 50 mx.backup.mailprotect.be
- TXT
-
mail-grant:ebhtsak50otzdjyac2mp6xnxpnw=hosting-site=recycle-2-bcb80salesforce-domain-verification=00D5J000001Quph=1TBQw00000003tz
- Verified for
-
- GlobalSign
Email authentication weak
- SPF
-
v=spf1 include:spf.mandrillapp.com include:_spf.salesforce.com ~allsoftfail (~all) - DMARC
- not published
- DKIM
- no key found at common selectors
Certificate (current)
GlobalSign RSA OV SSL CA 2018
Expires in 292 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- content-security-policy-report-only
- x-content-type-options
- referrer-policy
- findings
-
- short HSTS max-age
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing frame protection
- missing Permissions Policy
Header values
- referrer-policy
same-origin- x-content-type-options
nosniff- content-security-policy
default-src 'none'; script-src 'self' 'unsafe-inline' blob: https://www.recycleapp.be https://recycleapp.be https://*.googletagmanager.com https://js-cdn.dynatrace.com https://*.usercentrics.eu https://*.facebook.net; style-src 'self' 'unsafe-inline'; img-src 'self' data: blob: https://assets.recycleapp.be https://*.usercentrics.eu https://*.google-analytics.com https://*.googletagmanager.com https://*.facebook.com https://recycleapp.be https://www.recycleapp.be; connect-src 'self' https://api.mapbox.com https://events.mapbox.com https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com https://js-cdn.dynatrace.com https://api.fostplus.be/recyclecms/ https://*.ingest.sentry.io https://*.usercentrics.eu https://*.bf.dynatrace.com; worker-src 'self' blob:; child-src blob:; font-src 'self'; frame-ancestors *; manifest-src https://recycleapp.be https://www.recycleapp.be- strict-transport-security
max-age=10886400; includeSubDomains; preload- content-security-policy-report-only
default-src 'none'; script-src 'self' 'unsafe-inline' blob: https://www.recycleapp.be https://recycleapp.be https://*.googletagmanager.com https://js-cdn.dynatrace.com https://*.usercentrics.eu https://*.facebook.net; style-src 'self' 'unsafe-inline'; img-src 'self' data: blob: https://assets.recycleapp.be https://*.usercentrics.eu https://*.google-analytics.com https://*.googletagmanager.com https://*.facebook.com https://recycleapp.be https://www.recycleapp.be; connect-src 'self' https://api.mapbox.com https://events.mapbox.com https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com https://js-cdn.dynatrace.com https://api.fostplus.be/recyclecms/ https://*.ingest.sentry.io https://*.usercentrics.eu https://*.bf.dynatrace.com; worker-src 'self' blob:; child-src blob:; font-src 'self'; frame-ancestors 'self'; manifest-src https://recycleapp.be https://www.recycleapp.be; report-uri https://api.fostplus.be/recyclecms/v1/csp-violation
Linked from (2)
- fostplus.be×1
- olln.be×1