stiva.nl

.nl crawl

First seen 2026-05-20 · Last seen 2026-05-30 · ok HTTP/1.1 200 161 ms crawled 2026-05-27

NL · 84.22.103.111 · AS196752 Tilaa B.V.

Reputation 94/100 dmarc monitor-only

Classifying

HTML metadata

Title
Over STIVA - STIVA
Language
nl-NL
Canonical
https://stiva.nl/

Open Graph

url
https://stiva.nl/
title
Over STIVA - STIVA
locale
nl_NL
site name
STIVA
description
De Stichting Verantwoorde Alcoholconsumptie (STIVA) zet zich in voor verantwoorde alcoholconsumptie én verantwoorde alcoholreclame. Dat doen wij samen met de Nederlandse producenten en importeurs van bier, wijn en gedistilleerde dranken.  Hiermee maken we het kiezen voor een evenwichtige levensstijl makkelijker. En dat is belangrijk, want een evenwichtige levensstijl kan heel veel problemen in de toekomst […]

Technology

Server
nginx
CMS
WordPress
jQuery
3.7.1
Analytics
  • Google Tag Manager
Cookie consent
  • Cookiebot

Third-party hosts loaded (2)

  • consent.cookiebot.com×1
  • www.googletagmanager.com×1

DNS records live

NS
  • ns1.argewebhosting.eu
  • ns2.argewebhosting.com
  • ns3.argewebhosting.nl
MX
  • 0 stiva-nl.mail.protection.outlook.com

Email authentication partial

SPF
v=spf1 include:spf.protection.outlook.com include:_spf.shared.lvl.li include:mailgun.org -all
strict (-all)
DMARC
v=DMARC1; p=none;
policy: none (monitoring only)
DKIM
  • k2: v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAv2aC2KjGKLOwTweBY5A9RpjsxaBXR9r7OAU6U8/zn92ivImI75naUujWbItRI/QmL1jy5PWGqLwoUA…
selectors probed

Certificate (current)

E8
from 2026-05-04 to 2026-08-02
Expires in 63 days

HTTP security headers

Header hygiene 85/100 Checked live page: https://stiva.nl/

present
  • strict-transport-security
  • content-security-policy
  • x-frame-options
  • x-content-type-options
  • referrer-policy
findings
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
  • missing Permissions Policy
Header values
referrer-policy
strict-origin-when-cross-origin
x-frame-options
SAMEORIGIN
x-content-type-options
nosniff
content-security-policy
default-src https: data: blob:; script-src 'unsafe-inline' 'unsafe-eval' https: data:; style-src 'unsafe-inline' https: data:; img-src data: https: blob: android-webview android-webview-video-poster:; font-src data: https:; connect-src *; media-src https: data: blob:; worker-src https: blob:; frame-src 'self' https: blob:; frame-ancestors 'self'; upgrade-insecure-requests
strict-transport-security
max-age=63072000

Linked from (4)