alpecreativa.es

.es crawl

First seen 2026-04-11 · Last seen 2026-05-19 · ok HTTP/1.1 200 2907 ms crawled 2026-05-18

FR · 51.254.107.53 · AS16276 OVH SAS

Reputation 94/100 dmarc monitor-only

Classifying

HTML metadata

Title
Agencia de marketing y publicidad en Cantabria | Alpe Creativa
Description
Somos la agencia que no sabías que necesitabas: servicios de marketing, diseño y comunicación para tus proyectos.
Language
es
Generator
Site Kit by Google 1.178.0
Canonical
https://alpecreativa.es/

Open Graph

url
https://alpecreativa.es/
title
Agencia de marketing y publicidad en Cantabria | Alpe Creativa
locale
es_ES
site name
Alpe Creativa
description
Somos la agencia que no sabías que necesitabas: servicios de marketing, diseño y comunicación para tus proyectos.

Technology

Server
nginx
CMS
WordPress
Analytics
  • Google Tag Manager

Third-party hosts loaded (2)

  • www.googletagmanager.com×2
  • www.google.com×1

Social

Contact

Email
Phone

DNS records live

NS
  • ns3.dnsnetkia.es
  • ns4.dnsnetkia.es
MX
  • 0 alpecreativa-es.mail.protection.outlook.com
TXT
  • openai-domain-verification=dv-reJ6EM8iRI4ZLjisgeONBAn9
  • sophos-domain-verification=b68cf66505ca3fdbac16eb7f23c03ee469b8550616c743bba39b944da3563913

Email authentication partial

SPF
v=spf1 a mx include:_spf.prod.hydra.sophos.com include:spf.protection.outlook.com -all
strict (-all)
DMARC
v=DMARC1;p=none;
policy: none (monitoring only)
DKIM
  • selector1: v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCXFwd6FBmIQU/5pQMQolRZdg3aodSRVUJYTqW0TNiU3l9Vs7SFvF+8b7CY66vdn/MydnMFc7SgfF+jCxKhzi…
  • selector2: v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDFkSbedXZdjRMovwDWE3aRfi+WmXzJo376xJhewz+/JItM3TIRVRuY+kEmoCNxn4rmwuYKD0yvWJ0QUp65Q4…
selectors probed

Certificate (current)

Sectigo Public Server Authentication CA DV R36
from 2025-08-26 to 2026-09-21
Expires in 124 days

HTTP security headers

Header hygiene 85/100 Checked live page: https://alpecreativa.es/

present
  • strict-transport-security
  • content-security-policy
  • x-frame-options
  • x-content-type-options
  • referrer-policy
  • permissions-policy
findings
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
  • weak frame protection
Header values
referrer-policy
same-origin
x-frame-options
SAMEORIGIN, SAMEORIGIN
permissions-policy
accelerometer=*, ambient-light-sensor=(), autoplay=*, battery=(), camera=(), cross-origin-isolated=(), display-capture=(), document-domain=(), encrypted-media=*, execution-while-not-rendered=(), execution-while-out-of-viewport=(), fullscreen=*, geolocation=(), gyroscope=*, keyboard-map=(), magnetometer=(), microphone=(), midi=(), navigation-override=(), payment=(), picture-in-picture=*, publickey-credentials-get=(), screen-wake-lock=(), sync-xhr=(), usb=(), web-share=(), xr-spatial-tracking=()
x-content-type-options
nosniff
content-security-policy
frame-ancestors 'self';, default-src 'self' https://cdn.lordicon.com/ *.google-analytics.com https://yoast.com/; script-src 'self' 'unsafe-inline' 'unsafe-eval' data: blob: https://alpecreativa.es/ https://trackcmp.net https://diffuser-cdn.app-us1.com https://prism.app-us1.com/ https://www.youtube.com/ https://www.youtube.com/iframe_api https://www.googletagmanager.com/ https://ajax.googleapis.com/ https://cdn.lordicon.com/ *.google-analytics.com https://cdn.ampproject.org/ *.google.com *.gstatic.com; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com/ *.gstatic.com https://cdn.ampproject.org/ https://maxcdn.bootstrapcdn.com/ *.google-analytics.com *.google.com; connect-src 'self' data: https://yoast.com/ https://cdn.ampproject.org/ *.google-analytics.com *.google.com *.yoast.com *.gstatic.com; frame-src 'self' data: blob: https://alpecreativa.es/ https://www.youtube.com https://www.youtube-nocookie.com *.google.com *.gstatic.com *.yoast.com *.muffingroup.com https://www.go
strict-transport-security
max-age=31536000; includeSubDomains; preload

Links to (9)

Linked from (20)