bu.com.co
HTML metadata
Technology
- CDN
- Amazon CloudFront
- Server
- nginx
- CMS
- Drupal
- Analytics
-
- Google Tag Manager
Third-party hosts loaded (3)
- www.googletagmanager.com×2
- www.recaptcha.net×2
- d335luupugsy2.cloudfront.net×1
Social
Contact
- Phone
- Address
- rd Urrutia 2021
DNS records live
- NS
-
- ns1.bdm.microsoftonline.com
- ns20.columbus-networks.com
- ns22.columbus-networks.com
- MX
-
- 0 mxa.global.inbound.cf-emailsecurity.net
- 0 mxb.global.inbound.cf-emailsecurity.net
- TXT
-
Show 5 TXT records
Sendinblue-code:6606b053a71b13c57a219bcd852b13f7google-site-verification=MPcfh-GPduZf_ymd9pT_z-TI_r5od0nTVVLqxCplBIMVKpE8wBD83MUhbIYjQaVXXdLFW0wiWdKGl8njB3x+dowAd44kP6QQWGV6d23aeINvpdTZUnGsEuWm8HTBXb0uA==smartfense-domain-verification=Db9eNLxdYP5tFvySjdphXDKli7UO5BjryXCim15YtdsKtAkZFoxit-domain-verification=454eef962a1e6ba7ac0a89b3828cc1ed
Email authentication partial
- SPF
-
v=spf1 ip4:190.131.245.101 include:spf.protection.outlook.com include:spf.mandrillapp.com include:_spf.google.com include:_spf.embluemail.com include:spf.sendinblue.com include:spf-us.emailsignatures365.com ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=none; rua=mailto:postmaster@bu.com.co;ruf=mailto:postmaster@bu.com.co; sp=none; aspf=s;policy: none (monitoring only) · sp=none - DKIM
-
Show 4 DKIM selectors
- selector1:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQC+gIvPEgkH3buoeuWMsTeAZ/FPSWGV0yx/6u24xfINbF8bmA9CVW7MIOweDsmF+X+fyVnMotHhOF2gNu02KH… - mail:
k=rsa;p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDeMVIzrCa3T14JsNY0IRv5/2V1/v2itlviLQBwXsa7shBD6TrBkswsFUToPyMRWC9tbR/5ey0nRBH0ZVxp+lsmTxid2Y2z… - s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAp9xap60LjLIr9rOPAIrlH4NCARnGyUdPJu0C19wp13N46Lde93VI5e54Gv7ZmpO3teZVfz9VPnpss6IHaf… - s2:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAwyMsZAWsWQa9Z7AGNPFAJkb9+rF+LURO85PkaZGd37id5TeE2D/VAPFCGZZAMkCCE1uolxtRUF+0RGbl9a…
selectors probed - selector1:
Certificate (current)
R10
Expired 259 days ago
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- short HSTS max-age
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- weak frame protection
- missing Permissions Policy
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
ALLOW-FROM https://bu.com.co/- x-content-type-options
nosniff- content-security-policy
default-src 'self' 'unsafe-inline' *.bu.com.co *.googletagmanager.com *.gstatic.com *.recaptcha.net *.doubleclick.net *.google.com *.google-analytics.com *.google.com.co *.bootstrapcdn.com data:; script-src 'self' 'unsafe-inline' *.googletagmanager.com *.cloudfront.net *.jsdelivr.net *.embluemail.com *.recaptcha.net *.google-analytics.com *.gstatic.com *.google.com; style-src 'self' 'unsafe-inline' *.googletagmanager.com *.cloudfront.net *.jsdelivr.net *.embluemail.com *.recaptcha.net *.google-analytics.com *.gstatic.com *.google.com *.googleapis.com *.bootstrapcdn.com; frame-src 'self' *.spotify.com *.google.com *.gstatic.com *.recaptcha.net www.recaptcha.net;; frame-ancestors 'self' *.spotify.com; font-src 'self' *.gstatic.com *.jsdelivr.net *.bootstrapcdn.com; connect-src 'self' *.embluemail.com *.google-analytics.com *.doubleclick.net *.google.com ; report-uri /report-csp-violation; upgrade-insecure-requests- strict-transport-security
max-age=2592000; includeSubDomains; preload