rosa.be
HTML metadata
Technology
- CDN
- Amazon CloudFront
Social
DNS records live
- NS
-
- ns-12.awsdns-01.com
- ns-1475.awsdns-56.org
- ns-1836.awsdns-37.co.uk
- ns-902.awsdns-48.net
- MX
-
- 1 aspmx.l.google.com
- 10 alt3.aspmx.l.google.com
- 10 alt4.aspmx.l.google.com
- 5 alt1.aspmx.l.google.com
- 5 alt2.aspmx.l.google.com
- TXT
-
mistral-domain-verification=707970b1059a89c0ef79eba185dd88df5ec6a806
- Verified for
-
- Anthropic
- Atlassian
- GlobalSign
- Meta
Email authentication no MX
- SPF
- not published
- DMARC
- not published
- DKIM
- no key found at common selectors
Certificate (current)
Amazon RSA 2048 M01
Expires in 179 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- cross-origin-opener-policy
- cross-origin-embedder-policy
- cross-origin-resource-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Permissions Policy
Header values
- referrer-policy
no-referrer- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
report-to default ;connect-src 'self' *.rosa.be *.rosa.be:9000 cognito-idp.eu-central-1.amazonaws.com builder.io cdn.builder.io maps.googleapis.com bam.eu01.nr-data.net qwik-insights.builder.io *.srv.whereby.com wss://*.srv.whereby.com *.hotjar.com *.hotjar.io wss://*.hotjar.com ;script-src 'self' 'unsafe-eval' 'unsafe-inline' js-agent.newrelic.com bam.eu01.nr-data.net maps.googleapis.com cdn.builder.io *.srv.whereby.com static.hotjar.com script.hotjar.com ;font-src 'unsafe-inline' 'self' fonts.gstatic.com *.srv.whereby.com script.hotjar.com ;style-src 'self' 'unsafe-inline' fonts.googleapis.com *.srv.whereby.com static.hotjar.com script.hotjar.com ;frame-src 'self' rosa-be.whereby.com ;img-src 'self' data: blob: *.rosa.be mt0.google.com mt1.google.com mt2.google.com mt3.google.com maps.googleapis.com maps.gstatic.com cdn.builder.io static.hotjar.com script.hotjar.com ;default-src 'self' ;base-uri 'self' ;form-action 'self' ;frame-ancestors 'none' ;worker-src 'self' ;child-src 'self' ;- strict-transport-security
max-age=31536000; includeSubDomains; preload- cross-origin-opener-policy
unsafe-none; report-to="default"- cross-origin-embedder-policy
credentialless; report-to="default"- cross-origin-resource-policy
same-origin
Links to (4)
- apple.com×1
- facebook.com×1
- google.com×1
- linkedin.com×1
Linked from (6)
- clstjean.be×1
- klstjan.be×1
- standuphysio.be×1
- chirec.be×1
- chuuclnamur.be×1
- harton.be×1