vandommelenbloemen.nl
HTML metadata
Technology
- Server
- Apache
- CMS
- Joomla
- jQuery
- 3.1.1 known XSS (<3.5)
- Stack
- PHP
- Analytics
-
- Google Tag Manager
- Social widgets
-
- Vimeo Embed
Third-party hosts loaded (2)
- player.vimeo.com×1
- www.googletagmanager.com×1
Social
Contact
DNS records live
- NS
-
- aragorn.downdijk.nl
- bilbo.downdijk.nl
- MX
-
- 5 mail.vandommelenbloemen.nl
- Verified for
-
Email authentication strong
- SPF
-
v=spf1 a mx a:vandommelenbloemen.nl ip4:92.119.30.21 ip6:2a09:b340::f816:3eff:fe12:de0d include:ehv-virt-downdijk-web0.nefos.cloud ?allneutral (?all) - DMARC
-
v=DMARC1; p=reject; pct=100; rua=mailto:abuse@downdijk.nlpolicy: reject (enforced) - DKIM
- no key found at common selectors
Certificate (current)
R13
Expires in 64 days
HTTP security headers
- present
-
- content-security-policy
- x-frame-options
- x-content-type-options
- findings
-
- missing HSTS
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
base-uri 'self'; default-src 'self'; script-src 'self' https://*.mediagroupholland.nl https://*.adroll.com https://*.vandommelenbloemen.nl https://*.webdevspecialist.com https://*.downdijk.nl https://*.facebook.net https://*.adnxs.com https://*.adroll.com https://*.google.com https://*.piwik.pro https://*.doubleclick.net https://*.googleadservices.com https://*.google.com https://*.google-analytics.com https://*.googletagmanager.com https://*.google.com https://*.gstatic.com 'unsafe-inline' 'unsafe-eval'; style-src 'self' https://*.mediagroupholland.nl https://*.adroll.com https://*.piwik.pro https://*.google.com https://*.vandommelenbloemen.nl https://*.webdevspecialist.com https://*.google.com https://*.googleapis.com 'unsafe-inline'; img-src 'self' data: https://*.mediagroupholland.nl https://*.googletagmanager.com https://*.bidswitch.net https://*.ml314.com https://*.tapad.com https://*.3lift.com https://ml314.com https://*.pubmatic.com https://*.doubleclick.net https://*.casalemed