remia.nl
HTML metadata
Technology
- Server
- Microsoft-IIS
- Analytics
-
- Google Tag Manager
- Fonts
-
- Google Fonts
Third-party hosts loaded (2)
- fonts.googleapis.com×2
- www.googletagmanager.com×1
Social
Contact
- Address
- rd op de meest voorkomende vragen.Vraag het aan Remia© Copyright 2011
DNS records live
- NS
-
- nsauth1.bit.nl
- nsauth2.bit.nl
- nsauth3.bit.org
- MX
-
- 100 mx1.bit.nl
- 200 mx2.bit.nl
- 300 mx3.bitnl.eu
- TXT
-
MS=6DB98A48D9A1BF7A3C7FE509D92FD645B94DF77FQuoVadis=eeee9830-e4ad-4a0a-a16e-5dd4a378eb61
- Verified for
-
- DocuSign
Email authentication strong
- SPF
-
v=spf1 ip4:213.125.224.28 ip4:46.243.31.228 include:spf-breaks-email.bit.nl include:spf.afas.online include:_spf.exsilia.net -allstrict (-all) - DMARC
-
v=DMARC1; p=reject; rua=mailto:itservicedesk@remia.nl; ruf=mailto:itservicedesk@remia.nl; fo=1:d:s; aspf=s; adkim=s;policy: reject (enforced) - DKIM
- no key found at common selectors
Certificate (current)
R13
Expires in 71 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN- permissions-policy
camera=(), clipboard-read=(), display-capture=(), encrypted-media=(self "https://www.youtube-nocookie.com" "https://www.youtube.com"), fullscreen=(self "https://www.youtube-nocookie.com" "https://www.youtube.com"), geolocation=(), magnetometer=(), microphone=(), midi=(), payment=(), publickey-credentials-get=(self), screen-wake-lock=(), usb=(), web-share=(self), xr-spatial-tracking=()- x-content-type-options
nosniff- content-security-policy
default-src 'self'; frame-ancestors 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://*.googletagmanager.com https://*.google-analytics.com https://*.facebook.net https://*.googleadservices.com https://*.doubleclick.net https://*.cloudflare.com https://*.jsdelivr.net https://*.google.com https://*.googleapis.com https://*.gstatic.com https://*.googlesyndication.com; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://*.readspeaker.com https://*.gstatic.com; font-src 'self' data: https://fonts.gstatic.com; img-src 'self' data: https: https://*.googleapis.com https://*.gstatic.com https://*.ggpht.com https://*.ytimg.com; connect-src 'self' https://*.analytics.google.com https://*.google-analytics.com https://*.googletagmanager.com https://*.google.com https://*.facebook.net https://*.facebook.com https://*.doubleclick.net https://*.googleapis.com https://*.googlesyndication.com; frame-src 'self' https://*.googletagmanager.com https://*.doubleclick.net http- strict-transport-security
max-age=31536000; includeSubDomains