stek-wonen.nl
HTML metadata
Technology
- Server
- Microsoft-IIS
- ASP.NET
- 4.0.30319
- jQuery
- 3.3.1 known XSS (<3.5)
- Analytics
-
- Google Tag Manager
- Cookie consent
-
- Cookiebot
Third-party hosts loaded (2)
- consent.cookiebot.com×1
- www.googletagmanager.com×1
Social
Contact
- Phone
DNS records live
- NS
-
- nsauth1.introweb.nl
- nsauth2.introweb.nl
- nsauth3.introweb.net
- MX
-
- 10 stekwonen-nl01b.mail.protection.outlook.com
- TXT
-
vxLJI0zkiiygxkjvFrZ2uN2ZlzSpGtmMdqP/310PK7NNHTTHK3ny7oeMeZT3UFz0SKxYpRNmmfTty29mOaqx8w==amazonses:g1g0zE0OHNW44z44+Ql24oZrPPHlKm9oZupuNzb+SEk=bw=GJ4bnClaffKI1mFRRiXI5q1jJ6mWM5TMlVkwtby8ZsQA
- Verified for
-
- Microsoft 365
Email authentication strong
- SPF
-
v=spf1 a ip4:87.236.4.7 ip4:195.72.120.192 ip6:2001:678:56c:1:195:72:120:192 ip4:195.72.120.189 ip4:195.72.120.191 ip4:195.72.120.109 ip4:195.72.120.110 ip4:80.250.140.161 ip6:2a01:b2e0:2::213 ip6:2a01:b2e0:2::82 ip4:84.241.165.186 ip4:185.51.192.213 ip4:84.241.168.190 ip4:185.28.59.22 ip4:185.51.192.82 ip4:80.250.128.0/24 ip6:2a00:ecc0::abba:0:0/96 ip4:80.250.142.37 ip4:80.250.142.66 ip6:2a01:b2e0:2::213 ip6:2a01:b2e0:2::82 ip6:2a00:ecc0::abba:0:0/96 include:amazonses.com include:spf.protection.outlook.com include:spf.mandrillapp.com include:_spf.mailgun.org include:_spf.eu.mailgun.org include:spf.topdesk.net include:spf.mailjet.com -allstrict (-all) - DMARC
-
v=DMARC1; p=quarantine; rua=mailto:dmarc_agg@vali.email;policy: quarantine - DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDdNQQKC7BFa37+c8KOo12VYCHjYQjdilOKHKiMeCxOzcQwA541E0Yll3jrcPJy46Z1iU6fvtRV61pFDky/UH… - selector2:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCj3cOGTvJVDfq+flgJzFll97ec4Ifrsbs/F26GuEGM2cxlweHt1Q3y7RRSBsTY+RdHtz5GHvNlIvfHoMbiP5…
selectors probed - selector1:
Certificate (current)
Sectigo Public Server Authentication CA DV R36
Expires in 191 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN- permissions-policy
vibrate=(), push=(), microphone=(), camera=(), payment=()- x-content-type-options
NOSNIFF- content-security-policy
default-src 'self';connect-src 'self' api.tolkie.nl app.tolkie.nl formulieren.stek-wonen.nl wcag.formulierenserveracc.nl *.hotjar.com *.hotjar.io wss://*.hotjar.com www.google-analytics.com region1.google-analytics.com stats.g.doubleclick.net consentcdn.cookiebot.com region1.analytics.google.com;script-src 'self' 'unsafe-inline' app.tolkie.nl tool.tolkie.nl consentcdn.cookiebot.com formulieren.stek-wonen.nl wcag.formulierenserveracc.nl *.hotjar.com *.hotjar.io embeddemo.formulierenserver.nl/ *.mailplus.nl www.google-analytics.com www.googletagmanager.com consent.cookiebot.com connect.facebook.net;frame-src 'self' tool.tolkie.nl app.tolkie.nl www.youtube.com formulieren.stek-wonen.nl wcag.formulierenserveracc.nl *.hotjar.com *.hotjar.io www.googletagmanager.com consentcdn.cookiebot.com e.issuu.com;style-src 'self' 'unsafe-inline' app.tolkie.nl tool.tolkie.nl formulieren.stek-wonen.nl wcag.formulierenserveracc.nl static.mailplus.nl consent.cookiebot.com;img-src 'self' 'unsafe-inline' dat- strict-transport-security
max-age=31536000; includeSubdomains