vhluas.de
HTML metadata
Technology
- Server
- nginx
- CMS
- Gatsby
Third-party hosts loaded (1)
- fd-cdn.nl×61
Social
Registration
- Updated
- 2023-05-24
- Name servers
-
- ns1.argewebhosting.eu.
- ns2.argewebhosting.com.
- ns3.argewebhosting.nl.
DNS records live
- NS
-
- ns1.argewebhosting.eu
- ns2.argewebhosting.com
- ns3.argewebhosting.nl
- MX
-
- 10 primary.yourfilter.nl
- 20 fallback.yourfilter.nl
- TXT
-
d365mktkey=QGxikUKQhhMwhBbnxikwVx4OO4G9qtSLTDOj0YpTQGkxHARICA-xuvSyWjpARcUcLAweYA
Email authentication strong
- SPF
-
v=spf1 include:_spf.yourfilter.nl -allstrict (-all) - DMARC
-
v=DMARC1;p=quarantinepolicy: quarantine - DKIM
-
- default:
v=DKIM1; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA2+OYRgVXbkV94zcW8hklxSMBQPj8de129q0MYpfKQkw1d9B7jcPWI8aM6eA/OZ8eiavjHRAceN1Ca0Q0e464U…
selectors probed - default:
Certificate (current)
GEANT TLS RSA 1
Expires in 16 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- cross-origin-opener-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Permissions Policy
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
DENY- x-content-type-options
nosniff- content-security-policy
worker-src 'self' blob:; style-src 'self' 'unsafe-inline' https://minio.fourdigits.nl/ https://fd-cdn.nl/ https://cdn.unibuddy.co/; default-src 'self' https://minio.fourdigits.nl/ https://fd-cdn.nl/; frame-src 'self' https://newassets.hcaptcha.com/ https://www.youtube.com/ https://*.dynamics.com/ https://tr.snapchat.com/ https://consent.cookiebot.eu/ https://consentcdn.cookiebot.eu/ https://player.vimeo.com/ https://sst.hvhl.nl/ https://unibuddy.co https://*.unibuddy.co https://unibuddy.com https://*.unibuddy.com; img-src 'self' data: blob: http://www.gravatar.com/ https://minio.fourdigits.nl/ https://fd-cdn.nl/ https://i.ytimg.com/ https://assets-eur.mkt.dynamics.com/ https://www.googletagmanager.com/ https://sst.hvhl.nl/ https://sst.vhluas.de/ https://sst.vhluas.com/ https://px.ads.linkedin.com/ https://*.dynamics.com/ https://*.doubleclick.net/ https://www.facebook.com/ https://hvhl.containers.piwik.pro/ https://www.google.com/ https://*.google.com/ https://www.google.nl/ https://ap- strict-transport-security
max-age=31536000; includeSubDomains- cross-origin-opener-policy
same-origin-allow-popups