bigbangmedia.es
HTML metadata
Technology
- CDN
- Azure Front Door
Third-party hosts loaded (3)
- cdnjs.cloudflare.com×7
- cloud.typography.com×2
- images.mediapro.tv×1
DNS records live
- NS
-
- ns1-07.azure-dns.com
- ns2-07.azure-dns.net
- ns3-07.azure-dns.org
- ns4-07.azure-dns.info
- MX
-
- 0 bigbangmedia-es.mail.protection.outlook.com
- TXT
-
Yl3xSVtBa0n8RC2hMxT+Q6qMO+wkT9WXRSQzxHIr/t1bBHfziT5ULizFOuuTLUjKCVyfM9vG3r6OlJcmKVeRmw==
- Verified for
-
- Atlassian
- GlobalSign
- Microsoft 365
Email authentication weak
- SPF
-
v=spf1 include:imagina-media.com -allstrict (-all) - DMARC
- not published
- DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA0vWUn8D1YlNpUWmEkWkUHUWJtP9HMtsbzhqallpFcdyFbNVX9qLk65scDthD07fsq1n4rXkwxzqdax…
selectors probed - selector1:
Certificate (current)
Sectigo Public Server Authentication CA DV R36
Expires in 303 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
Header values
- referrer-policy
same-origin- x-frame-options
SAMEORIGIN- permissions-policy
geolocation=(self), microphone=()- x-content-type-options
nosniff- content-security-policy
base-uri 'self'; child-src 'self'; connect-src 'self' https:; default-src 'self' https:; font-src 'self' https: data: https://cloud.typography.com https://fonts.gstatic.com; form-action 'self'; frame-src 'self' https://www.youtube.com https://www.youtube-nocookie.com https://youtu.be; img-src 'self' https: data:; media-src https://m.youtube.com https://vimeo.com https://www.youtube.com https://d21v263fkuo8rk.cloudfront.net https://vod-progressive.akamaized.net https://d16vhwy5squw7q.cloudfront.net https://player.vimeo.com https://fpdl.vimeocdn.com https://youtu.be https://vod-progressive-ak.vimeocdn.com; object-src 'self'; script-src https://maps.googleapis.com https://www.google-analytics.com https://apis.google.com https://www.youtube.com/iframe_api https://s.ytimg.com https://www.youtube.com https://images.mediapro.es https://www.googletagmanager.com 'self' https: data: 'unsafe-inline' 'unsafe-hashes' 'unsafe-eval'; style-src https://cloud.typography.com https://images.mediapro.es h- strict-transport-security
max-age=31536000; includeSubDomains