vanwijnen.nl
HTML metadata
Technology
- CDN
- Azure Front Door
- CMS
- Next.js
- JS framework
- Next.js
- Analytics
-
- Google Tag Manager
- Cookie consent
-
- Cookiebot
Third-party hosts loaded (4)
- edge.sitecorecloud.io×10
- consent.cookiebot.com×1
- edge-platform.sitecorecloud.io×1
- www.googletagmanager.com×1
Social
DNS records live
- NS
-
- ns1.kpn.net
- ns11.kpn.net
- MX
-
- 0 vanwijnen-nl.mail.protection.outlook.com
- TXT
-
zeno-domain-verification-ktk7dn=pymdKzggrkMDr7eo1Es6JLtpPMsd0EYtuhS0s+JHQKxgyCsfg8Jmb8rB7oWOawowR85By9XMnGKH75flkpaPjnPDBnLNO0y9ISICB3Nb0c8WRWg==
- Verified for
-
- Atlassian
- DocuSign
- Dynamics 365
- Microsoft 365
- Sitecore
Email authentication strong
- SPF
-
v=spf1 mx ip4:62.221.215.139 ip4:57.153.12.77 include:spf.protection.outlook.com include:spf_core.nbo.nl include:fm8638.fmspf.net -allstrict (-all) - DMARC
-
v=DMARC1; p=reject; rua=mailto:dmarc@vanwijnen.nl,mailto:rua+vanwijnen.nl@dmarc.barracudanetworks.com; ruf=mailto:dmarc@vanwijnen.nl,mailto:ruf+vanwijnen.nl@dmarc.barracudanetworks.com; sp=reject; fo=1; pct=10policy: reject (enforced) · pct=10 · sp=reject - DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDGZJeZCE1jrukkRqfxZb3yhU0eA4OhGfs0SrniD3tfA7TPEpntXIh57sPUjEfShz7NGkM2ivLfhltF/PWLa4…
selectors probed - selector1:
Certificate (current)
GeoTrust TLS RSA CA G1
Expires in 44 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Referrer Policy
Header values
- x-frame-options
DENY- permissions-policy
accelerometer=(), autoplay=(self), camera=(), clipboard-read=(), clipboard-write=(), geolocation=(self), gyroscope=(), magnetometer=(), microphone=(), payment=(), usb=(), xr-spatial-tracking=(), browsing-topics=()- x-content-type-options
nosniff- content-security-policy
script-src-attr 'self' 'unsafe-inline' *.vanwijnen.nl; form-action 'self'; base-uri 'self'; default-src *.sitecorecloud.io; frame-ancestors 'none'; object-src 'none'; script-src 'self' *.googletagmanager.com *.google.com *.google.nl *.gstatic.com snap.licdn.com 'sha256-MiUQ7RjLqZJzkJOspp1zd/JZR7Cx2DK2f6GIS8m63JU=' *.azureedge.net; style-src 'unsafe-inline' *.sitecorecloud.io *.azureedge.net maps.googleapis.com fonts.googleapis.com *.vanwijnen.nl *.dynamics.com; script-src-elem 'self' 'unsafe-inline' *.google.com *.google.nl *.googletagmanager.com snap.licdn.com *.fontawesome.com maps.googleapis.com *.piwik.pro *.dynamics.com *.vanwijnen.nl consent.cookiebot.com consentcdn.cookiebot.com imgsct.cookiebot.com *.azureedge.net *.doubleclick.net *.facebook.net www.facebook.com *.hotjar.com *.hotjar.io; img-src 'self' *.sitecorecloud.io *.azureedge.net maps.googleapis.com *.gstatic.com data: *.youtube.com vumbnail.com *.vimeo.com vimeo.com *.googletagmanager.com consent.cookiebot.com consentc- strict-transport-security
max-age=63072000