totallyhosted.nl
HTML metadata
Technology
- Server
- Apache
- jQuery
- 1.10.2 known XSS (<3.5)
- Stack
- CodeIgniter
Third-party hosts loaded (1)
- maxcdn.bootstrapcdn.com×1
Contact
- Phone
- Address
- TotallyHostedKeurenplein 41 – Box E95001069CDAmsterdam, Nederland
DNS records live
- NS
-
- ns1.webhosted.nl
- ns2.webhosted.net
- MX
-
- 10 filter.spamport.com
- 20 fallback.spamport.com
- Verified for
-
Email authentication strong
- SPF
-
v=spf1 a mx include:outgoing.spamport.com ip6:2a00:1ca8:15::/64 a ip4:91.195.80.0/24 ip4:91.195.81.0/24 ip4:46.249.36.0/24 ip4:91.199.167.0/24 include:nameweb.biz include:spf.yourdomainprovider.net -allstrict (-all) - DMARC
-
v=DMARC1; p=quarantine; sp=none; aspf=r; adkim=r; pct=100; fo=1; rf=afrf; ri=86400; rua=mailto:incoming-dmarc-reports@mailregulator.net; ruf=mailto:incoming-dmarc-reports@mailregulator.netpolicy: quarantine · sp=none - DKIM
-
- default:
v=DKIM1; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDh1WJpMjyKm98CZ5/4/9G1vcbBD1UP29WIoXfkcl7J6MkQgxiIzANE6geQX7Gea8LPNpzOfwMQhz/CXot/2/FYkEB9x…
selectors probed - default:
Certificate (current)
E7
Expires in 51 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Permissions Policy
Header values
- referrer-policy
no-referrer- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src platform.twitter.com www.facebook.com www.totallyhosted.net www.totallyhosted.nl 'self' 'unsafe-inline' www.google.com maps.googleapis.com www.gstatic.com maxcdn.bootstrapcdn.com; script-src connect.facebook.net platform.twitter.com platform.linkedin.com www.totallyhosted.net www.totallyhosted.nl 'self' 'unsafe-eval' 'unsafe-inline' maps.googleapis.com www.gstatic.com www.google.com www.google-analytics.com www.totallyhosted.nl; img-src chart.googleapis.com www.facebook.com *.twitter.com maps.gstatic.com maps.googleapis.com www.google-analytics.com www.totallyhosted.net www.totallyhosted.nl 'self' data:; style-src-elem 'unsafe-inline' www.gstatic.com www.totallyhosted.net www.totallyhosted.nl 'self' www.google.com *.googleapis.com maxcdn.bootstrapcdn.com; font-src fonts.gstatic.com fonts.googleapis.com maxcdn.bootstrapcdn.com www.totallyhosted.net www.totallyhosted.nl 'self'; connect-src wss://*.totallyhosted.nl:* wss://*.sinnerg.nl:* https://www.totallyhosted.nl https://ww- strict-transport-security
max-age=31536000