waterdrinker.nl
HTML metadata
Technology
- Server
- envoy
- CMS
- Gatsby
- Analytics
-
- Google Tag Manager
- Fonts
-
- Google Fonts
Third-party hosts loaded (3)
- waterdrinker-02.s3.amazonaws.com×8
- fonts.googleapis.com×1
- www.googletagmanager.com×1
Contact
DNS records live
- NS
-
- eloise.ns.cloudflare.com
- sterling.ns.cloudflare.com
- MX
-
- 10 d337893.a.ess.de.barracudanetworks.com
- 20 d337893.b.ess.de.barracudanetworks.com
- TXT
-
9OYrxoQK+q40ERFNq3Ao7aKsu9hX2qcXKHW+wlNgrJxZgCgMY7P9Q7RRcNmzmarYHBTs9r02GzdNdbMoFvzMlg==
- Verified for
-
- Atlassian
- Microsoft 365
Email authentication weak
- SPF
-
v=spf1 mx a ip4:31.193.176.2/32 ip4:109.109.101.142/32 ip4:188.92.61.228/32 ip4:62.148.170.226/32 ip4:188.92.61.237/32 ip4:185.30.237.181 ip4:5.39.185.32/29 ip4:176.62.199.18/32 ip4:103.2.140.123 include:servers.mcsv.net include:spf.icontroller.eu include:spf.protection.outlook.com include:spf.afas.online include:spf.ess.de.barracudanetworks.com -allstrict (-all) - DMARC
- not published
- DKIM
-
- k1:
k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDbNrX2cY/GUKIFx2G/1I00ftdAj713WP9AQ1xir85i89sA2guU0ta4UX1Xzm06XIU6iBP41VwmPwBGRNofhBVR+e6WHUo…
selectors probed - k1:
Certificate (current)
Sectigo Public Server Authentication CA DV R36
Expires in 267 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-content-type-options
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing frame protection
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-content-type-options
nosniff- content-security-policy
default-src 'self'; script-src 'nonce-aTckM2H8j9+9CCm8u8XUAuV6C2iEM6MJwNX2FDy99i4JBm/G' 'self' https://cdn.usersnap.com https://cdn.mxpnl.com https://static.hotjar.com https://script.hotjar.com https://*.sentry.io https://*.google-analytics.com https://*.googletagmanager.com https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://waterdrinker.vedero.nl/ https://crmv2.salesfeed.com https://*.mouseflow.com 'unsafe-eval' 'unsafe-inline'; style-src 'self' http://localhost:3030 https://fonts.googleapis.com https://static.hotjar.com https://script.hotjar.com 'unsafe-inline'; object-src 'none'; base-uri 'self'; connect-src 'self' https://*.google.at https://*.google.be https://*.google.bg https://*.google.ch https://*.google.co.uk https://*.google.cz https://*.google.de https://*.google.dk https://*.google.ee https://*.google.es https://*.google.fi https://*.google.fr https://*.google.gr https://*.google.hr https://*.google.hu https://*.google.ie https://*.google.it https- strict-transport-security
max-age=31536000