6things to fix
!No IPv6 (AAAA) record.▸
Add an AAAA record with your server's IPv6 address, or switch on IPv6 at your host or CDN (on Cloudflare it's on by default for proxied records).
!DMARC is p=none (monitor only) - tighten to quarantine/reject.▸
Use the aggregate reports to confirm your legitimate senders pass, then raise the policy to p=quarantine and finally p=reject.
Read the guide →!DNSSEC not enabled - enable it to prevent DNS spoofing.▸
Turn on DNSSEC at your DNS host, then publish the DS record at your registrar to complete the chain of trust.
Read the guide →!No HSTS header - add Strict-Transport-Security.▸
Send Strict-Transport-Security: max-age=31536000; includeSubDomains on every response, at your server or CDN edge.
Read the guide →!No Content-Security-Policy header.▸
Add a Content-Security-Policy. Start in Content-Security-Policy-Report-Only mode, refine it, then enforce.
Read the guide →!Missing X-Content-Type-Options: nosniff.▸
Add the header X-Content-Type-Options: nosniff to stop browsers MIME-sniffing responses.
Read the guide →DNS records
A46.182.180.5
AAAAnone
Nameserversken.ns.cloudflare.com.
lisa.ns.cloudflare.com.
MX10 mail.huisartsenpraktijkdemiddend.nl.
20 fallback.mijnserver.nl.
SOAken.ns.cloudflare.com. dns.cloudflare.com. 2414827742 10000 2400 604800 1800
Mail authentication
SPFv=spf1 a mx include:spf.mijnserver.nl ~allPass
DMARCpolicy: p=noneWarn
DKIMnot detected on common selectors-
DNSSEC
ZoneOff
IP intelligence
Primary IP46.182.180.5
Reverse DNSserver1.exacthost.nl.
TLS certificate
CertificateSSL.com · expires 2026-12-10 (81d)Valid
HTTP security headers
HTTPS redirectYes
HSTSNo
CSPNo
X-Content-TypeNo
X-Frame-OptionsNo
Referrer-PolicyNo
Permissions-PolicyNo
ServerMicrosoft-IIS/10.0
Add this badge to your site
<a href="https://nattvakt.com/report/huisartsenpraktijkdemiddend.nl"><img src="https://nattvakt.com/badge/huisartsenpraktijkdemiddend.nl.svg" alt="Domain health"></a>