alion.com.co
HTML metadata
Technology
- Server
- Apache
- CMS
- WordPress
- Analytics
-
- Google Tag Manager
- Fonts
-
- Font Awesome
- Google Fonts
Third-party hosts loaded (8)
- cdnjs.cloudflare.com×3
- cdn.hu-manity.co×2
- fonts.googleapis.com×2
- maps.google.com×2
- gmpg.org×1
- use.fontawesome.com×1
- www.google.com×1
- www.googletagmanager.com×1
Social
Contact
DNS records live
- NS
-
- ns47.domaincontrol.com
- ns48.domaincontrol.com
- MX
-
- 0 alion-com-co.mail.protection.outlook.com
- TXT
-
Show 7 TXT records
google-site-verification=c4mXX-ViUqFCdfDj4uHhaqpiuNhreillDa7IiOFipjcgoogle-site-verification=0DCPJtsnLHuv0Afjz_7IfOXlE39vuPLkrW047wjakDMMS=ms499833069g1ku39kc8flv71f1h2rngg07qfacebook-domain-verification=3h1wr28xa1019tvou5sm62vwfewtr7google-site-verification=V3IH8iNSBTUve9FwjjVGEDphZ0ZMQJdj8H7dqPj9neQ6aq68hea7r5usnl1h35p3dv29d
Email authentication strong
- SPF
-
v=spf1 include:spf.protection.outlook.com include:_spf.embluemail.com a:ns01.alion.com.co include:send.zcsend.net include:mail.zendesk.com -allstrict (-all) - DMARC
-
v=DMARC1; p=quarantine; rua=mailto:hostmaster@corona.com.co; ruf=mailto:infosec@corona.com.co; fo=0:1:d:s; adkim=s; aspf=spolicy: quarantine - DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCo0Yg7MHjpVON5qKXhJTpBTvE3LcONUEPonDirP/leUUQlApUajs0fjn/xMpSEr+gDZ1vubDcS7To8Pwmjpf…
selectors probed - selector1:
Certificate (current)
Go Daddy Secure Certificate Authority - G2
Expires in 52 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- cross-origin-opener-policy
- cross-origin-embedder-policy
- cross-origin-resource-policy
- findings
-
- CSP allows unsafe inline scripts/styles
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN- permissions-policy
geolocation=(), microphone=(), camera=(), payment=(), usb=()- x-content-type-options
nosniff- content-security-policy
default-src 'self' https: data: 'unsafe-inline' 'unsafe-eval'; img-src 'self' https: data: blob:; font-src 'self' https: data:; connect-src 'self' https:; frame-src 'self' https:; object-src 'none'; base-uri 'self'; frame-ancestors 'self'; upgrade-insecure-requests- strict-transport-security
max-age=31536000; includeSubDomains- cross-origin-opener-policy
unsafe-none- cross-origin-embedder-policy
unsafe-none; report-to='default'- cross-origin-resource-policy
cross-origin