veldboereenhoorn.nl
HTML metadata
Technology
- Stack
- PHP
- Analytics
-
- Google Tag Manager
- Fonts
-
- Google Fonts
Third-party hosts loaded (2)
- fonts.googleapis.com×2
- www.googletagmanager.com×1
Social
Contact
- Phone
DNS records live
- NS
-
- nsauth01.solcon.nl
- nsauth02.solcon.nl
- nsauth03.solcon.nl
- MX
-
- 50 d339301.a.ess.de.barracudanetworks.com
- 50 d339301.b.ess.de.barracudanetworks.com
- TXT
-
asap-site-verification-82e37309-706c-4532-9f08-1b5211bf872b
- Verified for
-
- Microsoft 365
Email authentication partial
- SPF
-
v=spf1 include:_spf.mlsend.com ip4:213.126.18.88/29 ip4:62.25.54.160/29 ip4:213.124.67.176/29 ip4:85.17.203.72 ip4:85.17.186.74 ip4:85.17.186.72 ip4:145.131.8.238 ip4:85.17.203.75 ip4:178.21.21.115 a:email.veldboereenhoorn.nl a:webshop.veldboereenhoorn.nl include:spf.protection.outlook.com include:spf.ess.de.barracudanetworks.com include:spf.ymlp.com a:mail.twikey.com -allstrict (-all) - DMARC
-
v=DMARC1; p=none; fo=1; rua=mailto:rua+veldboereenhoorn.nl@dmarc.barracudanetworks.com; ruf=mailto:ruf+veldboereenhoorn.nl@dmarc.barracudanetworks.compolicy: none (monitoring only) - DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAzPm6j+8bpQ1t64yDSV47AiVCE0zyJ/SSQk+B0yeLHer952hXTBhwCbV21e7KDdwfuYvWxoUmqcPb4R…
selectors probed - selector1:
Certificate (current)
E7
Expires in 69 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Permissions Policy
Header values
- referrer-policy
same-origin- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
report-uri /api/csp/report-violations;default-src 'self';connect-src 'self' www.google-analytics.com maps.googleapis.com www.google.com www.gstatic.com www.googletagmanager.com *.google-analytics.com;script-src 'self' 'unsafe-inline' www.google-analytics.com maps.googleapis.com www.google.com www.gstatic.com www.googletagmanager.com;style-src 'self' 'unsafe-inline' fonts.googleapis.com;img-src 'self' data: www.google-analytics.com maps.googleapis.com maps.gstatic.com www.googletagmanager.com;media-src 'self';font-src 'self' fonts.gstatic.com;object-src 'none';frame-src 'self' www.youtube.com player.vimeo.com www.google.com www.googletagmanager.com;frame-ancestors 'none';block-all-mixed-content;- strict-transport-security
max-age=63072000; preload;