banrep.gov.co
HTML metadata
Technology
- CMS
- Drupal
- Analytics
-
- Google Tag Manager
- Fonts
-
- Google Fonts
Third-party hosts loaded (4)
- d1b4gd4m8561gs.cloudfront.net×75
- fonts.googleapis.com×1
- static.addtoany.com×1
- www.googletagmanager.com×1
Social
Contact
- Phone
DNS records live
- NS
-
- ns1-08.azure-dns.com
- ns2-08.azure-dns.net
- ns3-08.azure-dns.org
- ns4-08.azure-dns.info
- MX
-
- 20 banrep-gov-co.mail.protection.outlook.com
- TXT
-
Show 24 TXT records
_97yq2dpcia4r4l313k5jnevgxbez2q2MS=ms17612400fRjGWaGV6avicw8aLI1LySRSOR0LfkEhWNZCcDSN+1pdrzsHd9+auyXEcIZOm6i/Yh276ksgFNAzkzvhmtSluA==L8X0G4PWF0JijFhmn/qAe5dLsOhqwYV/qXIZ4z1ttqmz4xkz967nvRVYsl5QLCFOFXzoF7007gh88AvjpjrHuA==cisco-ci-domain-verification=3c9934e274e53cd7e6837037446acf33310977358eae5f8e675d1167cde58077google-site-verification=5Lpcb_gXGm2gE1r-jzUqrE5yLinXE58eXA38LKl_Rckgoogle-site-verification=rO5rt7Dxn9GTeAbcd24UUhPVmlVhdx47OL3SLtvdqX4v=spf1 ip4:181.63.70.34 ip4:200.116.127.162 mx a:autodiscover.banrep.gov.co include:spf.protection.outlook.com -allDynatrace-site-verification=c6772f26-c413-44aa-a48f-dee550072d2e__vra895ee2b5s5t657nc239pkld8g6tt8vb4h1vrcrjage3c8jo7vvq9s124dv9k02jjemq2ku9ce7vMNePMrSbs6dysFCyo/aCXcXiWXjIj+5ZlrpVgWQvH+I=xcslnq0mvj5zcbby9c09kphqj004zw46_i7fj3wjg7l413m09z26k75hw02i7bk6bpcq4gdebvv7g78c4ob763khp4b02267gbil2laibg0rd8cf3ll0facebook-domain-verification=52sy3oiosc88i98512tclo7upi6lwqautodesk-domain-verification=k-RwoRLhUCTVgsS7dpf1_8e930pw0n80ix9w880hw3rbdsi4u8jr1luotqomhit2i21udgd1ansu4e3pu0msrg205efukdnusuigd0rpmiro-verification=165fd81f6f17595d886631d67c6829f7ba889112paloaltonetworks-site-verification=ce0f5bd559703b426faffb6acfbc359323de0dcb25d29bcd6cc49accb4b1c40e_q7zwewke7z1w5rmgzbe4r5u0bd783nj
Certificate (current)
GeoTrust EV RSA CA G2
Expires in 188 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- short HSTS max-age
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- weak frame protection
Header values
- referrer-policy
same-origin- x-frame-options
SAMEORIGIN, SAMEORIGIN- permissions-policy
geolocation=(self), microphone=()- x-content-type-options
nosniff- content-security-policy
report-uri /report-csp-violation, frame-ancestors www.banrep.gov.co totoro.banrep.gov.co quimbaya.banrep.gov.co youtube.com facebook.com livestream.com cdn.livestream.com vimeo.com player.vimeo.com www.linkedin.com www.instagram.com app.powerbi.com www.tiktok.com tiktok.com sf16-website-login.neutral.ttwstatic.com; font-src 'self' data: banrep.gov.co fonts.gstatic.com themes.googleusercontent.com; img-src 'self' data: cdn.jsdelivr.net *.metricool.com *.google.com live.staticflickr.com www.banrep.gov.co d1b4gd4m8561gs.cloudfront.net *.googletagmanager.com *.gstatic.com encrypted-tbn1.gstatic.com www.google-analytics.com maps.googleapis.com *.googleapis.com; default-src 'self' 'unsafe-inline' 'unsafe-eval' blob: data: embed-standalone.spotify.com *.perfdrive.com cdn.jsdelivr.net cdnjs.cloudflare.com cdn.botframework.com powerva.microsoft.com directline.botframework.com wss://directline.botframework.com embed.podcasts.apple.com open.spotify.com embedr.flickr.com live.staticflickr.com www.- strict-transport-security
max-age=1000, max-age=31536000;includeSubDomains