bibeseguro.com
HTML metadata
Technology
- Server
- nginx
- CMS
- WordPress
- Fonts
-
- Google Fonts
Third-party hosts loaded (2)
- fonts.googleapis.com×4
- fonts.gstatic.com×1
Social
Contact
- Phone
- Address
- Avda. de la Vega 15,28012
Registration
- Registrar
- PDR Ltd. d/b/a PublicDomainRegistry.com
- Created
- 2016-02-11
- Expires
- 2027-02-11 267 days left
- Updated
- 2026-01-13
- Name servers
-
- ns3.dnsnetkia.es
- ns4.dnsnetkia.es
DNS records live
- NS
-
- ns3.dnsnetkia.es
- ns4.dnsnetkia.es
- MX
-
- 10 mx-01-eu-central-1.prod.hydra.sophos.com
- 20 mx-02-eu-central-1.prod.hydra.sophos.com
- TXT
-
sophos-domain-verification=7c0e0ea9c35ab1b18f8e7102aa739abadda56ef3c9c394ca5d9b316e1806f756
Email authentication weak
- SPF
-
v=spf1 a include:spf.protection.outlook.com include:ofermail.es -allstrict (-all) - DMARC
- not published
- DKIM
-
- k1:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCwzfx2ox2Fl03G90qB6DVPdNy02raOrYkmh6wKIZwPYrQ/50WzQ+SfL/OnG3EzAWroSswtPu5NhiUMiCFGc7…
selectors probed - k1:
Certificate (current)
Sectigo Public Server Authentication CA DV R36
Expires in 99 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
same-origin- x-frame-options
SAMEORIGIN- permissions-policy
accelerometer=(), ambient-light-sensor=(), autoplay=(), battery=(), camera=(), cross-origin-isolated=(), display-capture=(), document-domain=(), encrypted-media=(), execution-while-not-rendered=(), execution-while-out-of-viewport=(), fullscreen=(), geolocation=(), gyroscope=(), keyboard-map=(), magnetometer=(), microphone=(), midi=(), navigation-override=(), payment=(), picture-in-picture=*, publickey-credentials-get=(), screen-wake-lock=(), sync-xhr=(), usb=(), web-share=(), xr-spatial-tracking=()- x-content-type-options
nosniff- content-security-policy
default-src 'self'; script-src 'unsafe-inline' 'unsafe-eval' 'self' *.googleapis.com *.cloudflare.com *.google.com *.googletagmanager.com *.gstatic.com *.youtube.com; style-src 'unsafe-inline' 'unsafe-eval' 'self' https://fonts.googleapis.com *.googleapis.com *.gstatic.com; connect-src 'self' *.yoast.com *.google-analytics.com *.google.com; font-src 'unsafe-inline' 'unsafe-eval' 'self' data: *.gstatic.com *.wp.com https://fonts.gstatic.com; frame-src 'self' blob: *.youtube.com *.youtube-nocookie.com https://bibeseguro.com/; img-src 'self' data: https://ps.w.org/ https://s.w.org https://secure.gravatar.com https://demo2.alpecreativa.es; worker-src 'self' blob:;- strict-transport-security
max-age=31536000; includeSubDomains
bibeseguro.com