vkg.nl
HTML metadata
Technology
- Server
- Apache
- CMS
- WordPress
- Analytics
-
- Google Tag Manager
Third-party hosts loaded (2)
- code.jquery.com×1
- www.googletagmanager.com×1
Social
Contact
- Phone
DNS records live
- NS
-
- ns0.transip.net
- ns1.transip.nl
- ns2.transip.eu
- MX
-
- 0 vkg-nl.mail.protection.outlook.com
- TXT
-
0uKNgFinpoBPSK2XO2vs2nRgONO2CDbM
Email authentication partial
- SPF
-
v=spf1 include:spf.protection.outlook.com include:spf.antispam-login.net include:_spf.mailplus.nl ip4:85.10.153.51 ip6:2a01:7c8:bb0b:1b3:5054:ff:feca:67b6 include:mailservers.letsbuildit.nl -allstrict (-all) - DMARC
-
v=DMARC1;p=quarantine;sp=none;pct=50;rua=mailto:dmarc@vkg.nl;ruf=mailto:rufdmarc@vkg.nl;ri=86400;aspf=r;adkim=r;fo=1policy: quarantine · pct=50 · sp=none - DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAmawSJAP2YDb0KCb4AydSMyandtlsrYaaBLpzSXv2SQr0ZkAhmIQe01y+6F8FEYdkTxcvuyeY9gtG4n… - selector2:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAzb5dVG/Pumk+2DM4YVL24EPBqEfVBvjSFBLoOzrTZAksTQYJ8AHavn8NLmH4Dd7QGw+7xZ8wTDoxM3…
selectors probed - selector1:
Certificate (current)
E8
Expires in 53 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Referrer Policy
Header values
- x-frame-options
DENY- permissions-policy
geolocation=(),midi=(),sync-xhr=(),microphone=(),camera=(),magnetometer=(),gyroscope=(),fullscreen=(self),payment=()- x-content-type-options
nosniff- content-security-policy
default-src 'none';script-src 'self' 'unsafe-inline' 'unsafe-eval' https://vkg.nl https://www.google.com/ https://www.gstatic.com/ https://www.googletagmanager.com/ https://www.google-analytics.com/ https://s.hstatic.nl https://*.cookiebot.com/;style-src 'self' 'unsafe-inline' https://vkg.nl https://code.jquery.com/;img-src 'self' https://vkg.nl https://ps.w.org/ https://secure.gravatar.com/ https://s.w.org/ https://www.google-analytics.com/ data: https://imgsct.cookiebot.com/;font-src 'self' https://vkg.nl data:;frame-src https://www.google.com/ https://9d312d01-12f2-4c1e-9d1c-8791b2265b2f.tools.hypotheekbond.nl/ https://consentcdn.cookiebot.com/ https://www.youtube.com/;manifest-src 'self';frame-ancestors 'none';base-uri 'none';form-action 'self' https://extranet2.vkg.com/ https://www.vkg.com; connect-src 'self' https://www.google-analytics.com/ https://region1.google-analytics.com/ https://region1.analytics.google.com/ https://consentcdn.cookiebot.com/ https://www.google.nl/;- strict-transport-security
max-age=31536000