vdkgroep.com
HTML metadata
Technology
- CDN
- Cloudflare
- Stack
- PHP
- Analytics
-
- Google Tag Manager
- Cookie consent
-
- Cookiebot
Third-party hosts loaded (2)
- consent.cookiebot.com×1
- www.googletagmanager.com×1
Social
Contact
- Phone
DNS records
Email authentication strong
- SPF
-
v=spf1 include:spf.protection.outlook.com include:_spf.hellodialog.com include:spf.eprov.eu include:mailgun.org include:spf.whih.nl include:spf.afas.online ip4:37.97.240.76 ip4:85.10.138.144 ip4:217.100.166.2 ip4:23.249.235.169 ip4:93.92.31.65 ip4:217.67.226.80 ip6:2a01:07c8:bb0b:0002:5054:00ff:fec5:1743 ip6:2a03:9700:8000::7:92 -allstrict (-all) - DMARC
-
v=DMARC1; p=reject; sp=reject; aspf=s; adkim=s; rua=mailto:dmarc010007@trustconnect.nl; ruf=mailto:dmarc010007@trustconnect.nl;policy: reject (enforced) · sp=reject - DKIM
-
- k2:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAv2aC2KjGKLOwTweBY5A9RpjsxaBXR9r7OAU6U8/zn92ivImI75naUujWbItRI/QmL1jy5PWGqLwoUA…
selectors probed - k2:
Certificate (current)
WE1
Expires in 29 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
Header values
- referrer-policy
origin-when-cross-origin- x-frame-options
SAMEORIGIN- permissions-policy
autoplay=(self), fullscreen=(self)- x-content-type-options
nosniff- content-security-policy
frame-ancestors 'self'; block-all-mixed-content;default-src 'self'; script-src 'self' 'report-sample' 'unsafe-inline' 'unsafe-eval' https://cdn.jsdelivr.net https://cdn.ckeditor.com https://cdn.form.io https://cdnjs.cloudflare.com https://consentcdn.cookiebot.com https://consent.cookiebot.com https://googletagmanager.com https://momentjs.com https://matomo.sumedia.nl https://tagmanager.google.com https://www.gstatic.com https://www.google.com https://www.googletagmanager.com https://static.hotjar.com https://script.hotjar.com https://share.transistor.fm/; style-src 'self' 'report-sample' 'unsafe-inline' cdn.ckeditor.com cdn.form.io cdn.jsdelivr.net cdnjs.cloudflare.com fonts.googleapis.com tagmanager.google.com www.googletagmanager.com; object-src 'none'; frame-src 'self' consentcdn.cookiebot.com www.googletagmanager.com youtube.com www.youtube.com https://share.transistor.fm/; child-src 'self' www.googletagmanager.com; img-src 'self' data: cdn.ckeditor.com- strict-transport-security
max-age=31536000; includeSubDomains