airbnb.es
HTML metadata
Technology
- Server
- nginx
- CMS
- Gatsby
Third-party hosts loaded (30)
- a0.muscache.com×92
- zh.airbnb.com×2
- ar.airbnb.com×1
- bg.airbnb.com×1
- com.airbnb.android×1
- d0a7e.airbnb.com×1
- de.airbnb.lu×1
- es-l.airbnb.com×1
- es.airbnb.com×1
- fr.airbnb.be×1
- fr.airbnb.ca×1
- fr.airbnb.ch×1
- ga.airbnb.ie×1
- he.airbnb.com×1
- hi.airbnb.co.in×1
- hr.airbnb.com×1
- it.airbnb.ch×1
- ka.airbnb.com×1
- kn.airbnb.co.in×1
- mk.airbnb.com×1
- mr.airbnb.co.in×1
- mt.airbnb.com.mt×1
- sk.airbnb.com×1
- sq.airbnb.com×1
- sw.airbnb.com×1
- th.airbnb.com×1
- www.airbnb.ae×1
- www.airbnb.am×1
- www.airbnb.at×1
- www.airbnb.az×1
DNS records live
- NS
-
- dns1.p04.nsone.net
- dns2.p04.nsone.net
- dns3.p04.nsone.net
- ns-1087.awsdns-07.org
- ns-1877.awsdns-42.co.uk
- ns-394.awsdns-49.com
- ns-949.awsdns-54.net
- TXT
-
_zlr4zglmriac2s944vrnkeug1fbwoazfacebook-domain-verification=z5t4llckztaonkyfp0vdp40ffvs2l7google-site-verification=CPmQwoRuNGQMgYJnXhrlez7yrsTvWPcfeV-2AD6s03g
Email authentication no MX
- SPF
-
v=spf1 -allstrict (-all) - DMARC
-
v=DMARC1;p=reject;sp=reject;pct=100;rua=mailto:a4v1jq9a@ag.dmarcian.com;ruf=mailto:a4v1jq9a@fr.dmarcian.com;aspf=r;adkim=r;fo=1;ri=3600policy: reject (enforced) · sp=reject - DKIM
- no key found at common selectors
Certificate (current)
DigiCert Global G2 TLS RSA SHA256 2020 CA1
Expires in 50 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- findings
-
- short HSTS max-age
- CSP uses wildcard sources
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
child-src blob:; connect-src 'self' https: wss://ws.airbnb.com wss://ws.airbnb.es https://netverify.com https://*.netverify.com wss: *.amap.com https://*.mapbox.com; default-src 'self' https: blob:; font-src 'self' data: https://*.muscache.com fonts.gstatic.com https://use.typekit.net https:; frame-src * https://*.cardinalcommerce.com; img-src 'self' https: data: https://*.mapbox.com blob:; media-src 'self' https: blob:; script-src 'self' 'unsafe-eval' https://a0.muscache.com https://cdn.siftscience.com https://ss.musthird.com https://t1.musthird.com https://bat.bing.com https://connect.facebook.net https://www.google-analytics.com https://www.googleadservices.com https://tpc.googlesyndication.com https://www.googletagmanager.com https://maps.googleapis.com https://ajax.googleapis.com https://*.g.doubleclick.net https://www.google.com https://www.gstatic.com https://smartlock.google.com https://accounts.google.com https://app.link https://cdn.branch.io https://api.branch.io https://bam- strict-transport-security
max-age=10886400; includeSubdomains