admiralbet.es
HTML metadata
Technology
- Server
- volt-adc
- Analytics
-
- Google Analytics
- Google Tag Manager
Third-party hosts loaded (7)
- admiralbet-es-cdn-static.gt-cdn.net×21
- www.googletagmanager.com×2
- c.oracleinfinity.io×1
- cdn.dfsdk.com×1
- cdn.optimizely.com×1
- rmg-crm-api-at.greentube.com×1
- www.google-analytics.com×1
DNS records live
- NS
-
- edns5.ultradns.biz
- edns5.ultradns.com
- edns5.ultradns.net
- edns5.ultradns.org
- ns0056.secondary.cloudflare.com
- ns0131.secondary.cloudflare.com
- MX
-
- 10 mx1.greentube.com
- 20 mx2.greentube.com
- TXT
-
v=spf1 include:spf.greentube.com mx include:u1975876.wl.sendgrid.net include:spf.protection.outlook.com -alle4kgh4f691dhct24d0uoh4triav16gh8d7qccfgfmcp27nhjkcpfks3g43
- Verified for
-
- Meta
- Microsoft 365
Certificate (current)
DigiCert Global G2 TLS RSA SHA256 2020 CA1
Expires in 182 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- cross-origin-opener-policy
- cross-origin-resource-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Permissions Policy
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src *;script-src * 'unsafe-inline' 'unsafe-eval';style-src * 'unsafe-inline';img-src * data: blob:;child-src * blob:;connect-src *;font-src * data:;object-src *;media-src *;frame-src *;base-uri *;form-action *;frame-ancestors *;script-src-attr *;upgrade-insecure-requests- strict-transport-security
max-age=31536000- cross-origin-opener-policy
same-origin- cross-origin-resource-policy
same-origin