4things to fix
!No IPv6 (AAAA) record.▸
Add an AAAA record with your server's IPv6 address, or switch on IPv6 at your host or CDN (on Cloudflare it's on by default for proxied records).
!DMARC is p=none (monitor only) - tighten to quarantine/reject.▸
Use the aggregate reports to confirm your legitimate senders pass, then raise the policy to p=quarantine and finally p=reject.
Read the guide →!No HSTS header - add Strict-Transport-Security.▸
Send Strict-Transport-Security: max-age=31536000; includeSubDomains on every response, at your server or CDN edge.
Read the guide →!No Content-Security-Policy header.▸
Add a Content-Security-Policy. Start in Content-Security-Policy-Report-Only mode, refine it, then enforce.
Read the guide →DNS records
A178.21.114.234
AAAAnone
Nameserversns0.transip.net.
ns1.transip.nl.
ns2.transip.eu.
MX101 aspmx.l.google.com.
105 alt1.aspmx.l.google.com.
105 alt2.aspmx.l.google.com.
110 aspmx2.googlemail.com.
110 aspmx3.googlemail.com.
SOAns0.transip.net. hostmaster.transip.nl. 2026050400 86400 1800 2419200 300
Mail authentication
SPFv=spf1 a ip4:149.202.83.44 ip4:168.245.58.142 ip4:213.125.184.76 ip6:fe80::ec4:7aff:fe6e:9c62 include:_spf.google.com include:spf.protection.outlook.com ~allPass
DMARCpolicy: p=noneWarn
DKIMnot detected on common selectors-
DNSSEC
Zone2 DNSKEY record(s)Signed
IP intelligence
Primary IP178.21.114.234
Reverse DNSweb07.johocenters.nl.
TLS certificate
CertificateLet's Encrypt · expires 2026-10-03 (32d)Valid
HTTP security headers
HTTPS redirectYes
HSTSNo
CSPNo
X-Content-TypeYes
X-Frame-OptionsYes
Referrer-PolicyNo
Permissions-PolicyNo
ServerApache