sakura.eu
HTML metadata
Technology
- Server
- Microsoft-IIS
- Analytics
-
- Google Tag Manager
Third-party hosts loaded (2)
- www.google.com×2
- www.googletagmanager.com×1
Social
Contact
- Address
- Flemingweg 10A2408 AV Alphen aan den RijnThe Netherlands
DNS records live
- NS
-
- ns0.transip.net
- ns1.transip.nl
- ns2.transip.eu
- MX
-
- 0 sakura-eu.mail.protection.outlook.com
- TXT
-
nordpass-domain-verification=89667a3f33b048eabb54b91ba35d5de7
- Verified for
-
- Apple
- DocuSign
- TeamViewer
Email authentication strong
- SPF
-
v=spf1 ip4:154.52.2.6 a:mx.na1.hgncloud.com a:malengo.exception.mx a:smtp.courseware.nl include:spf_c.oraclecloud.com include:spf.protection.outlook.com include:_spf.inception.nl include:mail.zendesk.com ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=quarantine; rua=mailto:dmarc_rua@sakura.eu; ruf=mailto:dmarc_ruf@sakura.eu; sp=reject; fo=1policy: quarantine · sp=reject - DKIM
-
- selector2:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDIiEvncvDFv/zxHJk2MoKKDFLjfIyuHs9Uaxkdu//LSXq7Iuk7zcUDUGwvS03MSnWk1kn1rdjIFsOkOL0gSy… - k1:
k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDbNrX2cY/GUKIFx2G/1I00ftdAj713WP9AQ1xir85i89sA2guU0ta4UX1Xzm06XIU6iBP41VwmPwBGRNofhBVR+e6WHUo…
selectors probed - selector2:
Certificate (current)
Sectigo Public Server Authentication CA DV R36
Expires in 178 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing content type protection
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
SAMEORIGIN- content-security-policy
script-src 'self' 'unsafe-inline' 'unsafe-eval' https://*.googletagmanager.com https://*.google-analytics.com https://js.monitor.azure.com https://*.bing.com https://*.hotjar.com https://www.clarity.ms https://*.doubleclick.net https://*.google.com https://*.gstatic.com;style-src 'self' 'unsafe-inline' ;img-src 'self' data: https://*.fls.doubleclick.net https://www.facebook.com https://*.google-analytics.com https://*.google.analytics.com https://*.analytics.google.com https://*.googletagmanager.com https://*.bing.com https://*.vimeocdn.com https://*.google.com https://*.google.nl https://*.hotjar.com;connect-src 'self' https://dc.services.visualstudio.com https://*.google-analytics.com https://*.google.analytics.com https://*.facebook.com/ https://*.analytics.google.com https://*.googlesyndication.com https://*.clarity.ms https://*.bing.com https://*.google.com https://*.doubleclick.net https://*.hotjar.com wss://*.hotjar.com https://*.hotjar.io https://js.monitor.azure.com https:/- strict-transport-security
max-age=31536000; includeSubDomains