Skip to Content
Q&A

A 100% score on internet.nl: Here’s how to get all the checkmarks to turn green

DNSSEC, SPF, DMARC, DKIM, STARTTLS, DANE, IPv6 — from a red page to 100% in a single coordinated sprint.

Terug naar alle Q&A
June 16, 2026 by
A 100% score on internet.nl: Here’s how to get all the checkmarks to turn green
DAADit Group, Nick

U test uw domein op internet.nl, verwacht een net rapport en krijgt een pagina vol rode en oranje vinkjes: 67% of lager. Herkenbaar — en er is goed nieuws: vrijwel elk vinkje is in één gecoördineerde sprint groen te krijgen, vaak zonder dat u zelf een regel code hoeft te schrijven. Hieronder de aanpak die wij bij klanten gebruiken.

Wat meet internet.nl eigenlijk?

Internet.nl is een initiatief van onder meer de Nederlandse overheid en toetst uw domein op moderne internetstandaarden in drie categorieën: website (encryptie en beveiligingsheaders), mail (echtheid en versleuteling van e-mail) en verbinding (IPv6 en DNSSEC). Het is geen theoretisch keurmerk. Een ontbrekend SPF- of DMARC-record betekent in de praktijk dat criminelen namens uw domein kunnen mailen — en dat uw eigen offertes vaker in de spam belanden.

Website: moderne encryptie en veilige headers

Dit regelt u bij uw hoster of in uw webserverconfiguratie. Activeer TLS 1.2 en 1.3 en schakel TLS 1.0/1.1 uit. Forceer een redirect van http naar https en zet daarna de beveiligingsheaders aan: HSTS, CSP (Content-Security-Policy), X-Content-Type-Options en X-Frame-Options. Bij Odoo Online staat het meeste hiervan al goed; draait uw site op een eigen server of achter een proxy, dan loont een extra check.

Mail: SPF, DKIM, DMARC, STARTTLS en DANE

Hier zit de meeste winst — en het meeste risico als u het overhaast. Voeg bij uw DNS-provider een SPF-record toe dat uitsluitend uw bekende verzenders toestaat (Odoo-SMTP, Microsoft 365, Mailgun, enz.). Activeer DKIM per mailprovider en publiceer de sleutel als TXT-record. Zet DMARC eerst op p=none om vier weken te monitoren, en verhoog daarna naar p=quarantine of liefst p=reject. STARTTLS en DANE (een TLSA-record) stelt u in op de mailserver zelf; bij Microsoft 365 en de meeste Nederlandse mailhosters is dit inmiddels standaard of een kwestie van een supportticket.

Verbinding: IPv6 en DNSSEC

De snelste winst zit vaak hier. Laat uw hoster AAAA-records (IPv6) en DNSSEC inschakelen — bij de meeste Europese providers is dat letterlijk een tickbox. Een logische volgorde voor de hele sprint:

  1. DNSSEC en IPv6 — de grootste quick wins, vrijwel geen risico.
  2. SPF + DKIM + DMARC — start met p=none, na vier weken testen door naar reject.
  3. STARTTLS en DANE op de mailserver.
  4. Web-beveiligingsheaders en TLS-hardening als afronding.

Blijf hertesten

Tip: laat het niet bij die ene 100% — plan ieder kwartaal een hertest. Providers wijzigen configuraties (een nieuw mailserver-IP bijvoorbeeld) en uw SPF-record kan stilletjes breken, waardoor uw mail in de spam belandt zonder dat u het merkt. Gebruik gratis DMARC-rapportages (bijvoorbeeld via Postmark of Dmarcian) om te zien wie er namens uw domein probeert te versturen. Hulp nodig bij die eerste sprint naar 100%? Neem contact op met DAADit Group — wij brachten dit traject al vaker van rood naar groen.

You test your domain on internet.nl, expect a tidy report and get a page full of red and orange checkmarks: 67% or lower. Recognisable — and there is good news: almost every checkmark can turn green in a single coordinated sprint, often without writing a line of code yourself. Below is the approach we use with our clients.

What does internet.nl actually measure?

Internet.nl is an initiative backed by, among others, the Dutch government. It tests your domain against modern internet standards in three categories: website (encryption and security headers), mail (authenticity and encryption of e-mail) and connection (IPv6 and DNSSEC). It is not a theoretical badge. A missing SPF or DMARC record means, in practice, that criminals can send e-mail on behalf of your domain — and that your own quotations land in spam more often.

Website: modern encryption and secure headers

You arrange this at your host or in your web server configuration. Activate TLS 1.2 and 1.3 and disable TLS 1.0/1.1. Force a redirect from http to https, then enable the security headers: HSTS, CSP (Content-Security-Policy), X-Content-Type-Options and X-Frame-Options. On Odoo Online most of this is already in order; if your site runs on your own server or behind a proxy, an extra check pays off.

Mail: SPF, DKIM, DMARC, STARTTLS and DANE

This is where the biggest gains are — and the biggest risk if you rush it. At your DNS provider, add an SPF record that only allows your known senders (Odoo SMTP, Microsoft 365, Mailgun, etc.). Activate DKIM per mail provider and publish the key as a TXT record. Set DMARC to p=none first and monitor for four weeks, then raise it to p=quarantine or preferably p=reject. STARTTLS and DANE (a TLSA record) are configured on the mail server itself; with Microsoft 365 and most Dutch mail hosts this is now standard or a matter of one support ticket.

Connection: IPv6 and DNSSEC

The quickest wins are often here. Have your host enable AAAA records (IPv6) and DNSSEC — with most European providers this is literally a tickbox. A sensible order for the whole sprint:

  1. DNSSEC and IPv6 — the biggest quick wins, virtually no risk.
  2. SPF + DKIM + DMARC — start with p=none, move to reject after four weeks of testing.
  3. STARTTLS and DANE on the mail server.
  4. Web security headers and TLS hardening to finish.

Keep retesting

Tip: don't stop at that one 100% — schedule a retest every quarter. Providers change configurations (a new mail server IP, for example) and your SPF record can silently break, sending your mail to spam without you noticing. Use free DMARC aggregate reports (for example via Postmark or Dmarcian) to see who is trying to send on behalf of your domain. Need help with that first sprint to 100%? Contact DAADit Group — we have taken this journey from red to green more than once.

Vraag niet beantwoord?

Onze Odoo-consultants denken graag met u mee. Plan een vrijblijvend kennismakingsgesprek.

Plan een afspraak
Goods Receipt in 3 Steps: receipt → quality → stock
For those who don't want to put all the items they receive in the right place right away.