HeaderAudit
A

rijksoverheid.nl

Score 100/100 · scanned 2026-08-04

Content-Security-Policy

rijksoverheid.nl sends an enforcing CSP. It is nonce-based.

default-src 'self'; img-src 'self' data: blob: https://statistiek.rijksoverheid.nl https://*.rovid.nl https://*.rijksoverheidsvideo.nl https://d3oiud1b8fohdw.cloudfront.net https://www.toegankelijkheidsverklaring.nl www.rovid.nl rijksoverheid.origin.p25e.nl www.rijksoverheid.nl voorlichting-rijksoverheid.origin.p25e.nl; object-src 'none'; frame-ancestors 'self'; form-action 'self' https://*.rijksoverheid.nl https://*.contenttoolsrijksoverheid.nl; style-src 'self' 'unsafe-inline' https://statistiek.rijksoverheid.nl https://*.contenttoolsrijksoverheid.nl; style-src-elem 'self' 'unsafe-inline' https://statistiek.rijksoverheid.nl https://*.contenttoolsrijksoverheid.nl; style-src-attr 'unsafe-inline'; font-src 'self' data: https://statistiek.rijksoverheid.nl; connect-src 'self' https://*.rijksoverheid.nl https://*.platformrijksoverheid.nl https://*.contenttoolsrijksoverheid.nl https://statistiek.rijksoverheid.nl https://*.rovid.nl https://*.rijksoverheidsvideo.nl https://export.highcharts.com https://static.nederlandwereldwijd.nl https://*.p1o.nl https://api1.abonneren.platformrijksoverheidonline.nl/ https://*.rijksoverheid.nl; script-src 'self' 'nonce-ZWRiMTEyM2ItYzAxYy00ZjZkLWJmZmYtOTc0MWRkYzU5ZmE3' https://statistiek.rijksoverheid.nl https://*.rijksoverheid.nl https://*.platformrijksoverheid.nl https://*.contenttoolsrijksoverheid.nl; media-src 'self' https://*.rovid.nl https://*.rijksoverheidsvideo.nl; base-uri 'self'; upgrade-insecure-requests;
DirectiveSources
default-src'self'
img-src'self' data: blob: https://statistiek.rijksoverheid.nl https://*.rovid.nl https://*.rijksoverheidsvideo.nl https://d3oiud1b8fohdw.cloudfront.net https://www.toegankelijkheidsverklaring.nl www.rovid.nl rijksoverheid.origin.p25e.nl www.rijksoverheid.nl voorlichting-rijksoverheid.origin.p25e.nl
object-src'none'
frame-ancestors'self'
form-action'self' https://*.rijksoverheid.nl https://*.contenttoolsrijksoverheid.nl
style-src'self' 'unsafe-inline' https://statistiek.rijksoverheid.nl https://*.contenttoolsrijksoverheid.nl
style-src-elem'self' 'unsafe-inline' https://statistiek.rijksoverheid.nl https://*.contenttoolsrijksoverheid.nl
style-src-attr'unsafe-inline'
font-src'self' data: https://statistiek.rijksoverheid.nl
connect-src'self' https://*.rijksoverheid.nl https://*.platformrijksoverheid.nl https://*.contenttoolsrijksoverheid.nl https://statistiek.rijksoverheid.nl https://*.rovid.nl https://*.rijksoverheidsvideo.nl https://export.highcharts.com https://static.nederlandwereldwijd.nl https://*.p1o.nl https://api1.abonneren.platformrijksoverheidonline.nl/ https://*.rijksoverheid.nl
script-src'self' 'nonce-ZWRiMTEyM2ItYzAxYy00ZjZkLWJmZmYtOTc0MWRkYzU5ZmE3' https://statistiek.rijksoverheid.nl https://*.rijksoverheid.nl https://*.platformrijksoverheid.nl https://*.contenttoolsrijksoverheid.nl
media-src'self' https://*.rovid.nl https://*.rijksoverheidsvideo.nl
base-uri'self'
upgrade-insecure-requests(empty)

Headers sent

HeaderValue
strict-transport-securitymax-age=31536000 ; includeSubDomains
x-frame-optionsdeny
x-content-type-optionsnosniff
referrer-policystrict-origin-when-cross-origin
permissions-policyaccelerometer=(), autoplay=(), camera=(), document-domain=(), geolocation=(), gyroscope=(), magnetometer=(), microphone=(), midi=(), payment=(), picture-in-picture=self, publickey-credentials-get=(), …
cross-origin-opener-policysame-origin

Re-scan live

This is a snapshot from 2026-08-04. Check it now: