bragamat.es
HTML metadata
Technology
- Server
- nginx
DNS records live
- NS
-
- emely.ns.cloudflare.com
- gerald.ns.cloudflare.com
- MX
-
- 10 mx.zoho.com
- 20 mx2.zoho.com
- 50 mx3.zoho.com
- TXT
-
zoho-verification=zb17684672.zmverify.zoho.comProbely=e5029630-85dc-4738-8961-9ba5b231a65cgoogle-site-verification=5_kLwyoxLxpNCStqtm63BiMpjc-KrqT2uimOcrL_r-I
Email authentication strong
- SPF
-
v=spf1 include:zoho.com include:amazonses.com ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=reject; rua=mailto:dmarc@bragamat.es; ruf=mailto:dmarc@bragamat.es; sp=reject; adkim=r; aspf=rpolicy: reject (enforced) · sp=reject - DKIM
- no key found at common selectors
Certificate (current)
E7
Expires in 38 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
strict-origin- x-frame-options
DENY- permissions-policy
accelerometer=(), camera=(self "https://verify.didit.me" ), geolocation=(self ), gyroscope=(), magnetometer=(), microphone=(self "https://verify.didit.me" ), usb=()- x-content-type-options
nosniff- content-security-policy
default-src 'self'; img-src 'self' data: blob: https://www.google.com https://*.google-analytics.com https://*.googletagmanager.com https://*.b-cdn.net https://*.webankieta.pl https://*.startquestion.com https://*.clarity.ms https://c.bing.com https://www.bragamat.es https://www.google.es https://widget.mondialrelay.com https://www.mondialrelay.com https://*.openstreetmap.org; media-src 'self' https://*.b-cdn.net ; font-src 'self' data: https://fonts.gstatic.com ; style-src 'self' 'unsafe-inline' https://widget.mondialrelay.com https://unpkg.com/leaflet/dist/leaflet.css https://fonts.googleapis.com/css2; script-src 'self' 'nonce-71709252b38e58127de48ce9e8b25da7' https://www.google.com https://www.gstatic.com https://www.google-analytics.com https://*.googletagmanager.com https://*.startquestion.com https://*.clarity.ms 'sha256-fW3jg6O3U7PumNqbyb1Zg7VSKpkp1BB137OZieFFaFc=' 'sha256-tdgIcXcpV20vu1f3CsbrseMSwER/xuoGBq4x9PbG8Z4=' https://widget.mondialrelay.com https://ajax.googleapis.com/a- strict-transport-security
max-age=63072000; includeSubdomains; preload
Linked from (2)
- erog.es×4
- xgay.com.es×2