bvc.com.co
HTML metadata
Technology
- CDN
- Amazon CloudFront
- Server
- *
- CMS
- Next.js
- Analytics
-
- Google Tag Manager
Third-party hosts loaded (1)
- www.googletagmanager.com×1
DNS records live
- NS
-
- juno.impsat.net.co
- ns1.impsat.net.co
- MX
-
- 1 aspmx.l.google.com
- 10 alt3.aspmx.l.google.com
- 10 alt4.aspmx.l.google.com
- 5 alt1.aspmx.l.google.com
- 5 alt2.aspmx.l.google.com
- TXT
-
Show 6 TXT records
v=DKIM1;p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAk/eiVaeK2WjL7SWwTFMGgxfYW/xk452kw1ouch7tQ0af3ZVh3ZKoJNaJrJ3kdw7ng8oXS94CF7a8FZpxZmFeV66uJ2zpzfxAnxYM5ay6K9n7d/beQjAeyMkhVr8rF6GJnlPSlSJstosyFq8CmksnriwG196bcxHOEOQiGZbcL49nau4r0IJxHo/Lav1dHBiDrLSMamKiF1Zl90Vp1kaxE8mUTBwylsdK/yMto6l9SY3QjA+uISrFEVvrXxMoWOBsulL3+DnyadPBo4/djvDrSpMknaia31R9fvv93AByjswSVrbsTlZhY6zH68MfgpMBMvkDD2oLFKX83ZQGwtKYQwIDAQABamazonses:Ohw1hyyrH7nKXqTUHSAwlZXZV4Z50APoyKrt34QIhWI=amazonses:817gl+Vux5fMg4nTZ+52LH1n/FoULxQkCnNDjv0C3Qc=y2Dg9XcD7nVSjVrz9vtQ3Q==amazonses:Nc5q+qGKEYyJy3doLXbaBgAl4ZvU/SPr+mLteSNKeqA=amazonses:6UgFDO2rs8PJUNaYCtSSwHYlHP5S1Z4Nj5ZADNqEQ94=
- Verified for
-
- Atlassian
- Dynatrace
- Microsoft 365
- Zoom
Email authentication strong
- SPF
-
v=spf1 include:bvc-com-co.spf.smtp25.com include:_spf.google.com include:_spf.qualtrics.com include:_spf.elasticemail.com include:zcsend.net ip4:142.0.162.0/24 ip4:200.1.81.109/32 ip4:200.1.86.109/32 ip4:190.143.91.200/32 include:amazonses.com -allstrict (-all) - DMARC
-
v=DMARC1; p=quarantine; rua=mailto:bvc-windows@bvc.com.co; pct=75; adkim=r; aspf=rpolicy: quarantine · pct=75 - DKIM
-
Show 4 DKIM selectors
- google:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAjhtALxcYyIx6dpmMzZaPpI3+/cveDtF+UVpc4VcH6cEzoFpgZvnhY62GTWU5zgUFIhkazdzPfbr992… - k2:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAv2aC2KjGKLOwTweBY5A9RpjsxaBXR9r7OAU6U8/zn92ivImI75naUujWbItRI/QmL1jy5PWGqLwoUA… - s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAwLfpXLAI6e4zeNwdATVGGQO/6lv5yFkbvu+u47cQ/OGQWJ6DQb1nZlymT/HwKO/HXDruUId68+YIDpGktc… - s2:
k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCkUhWWQc+uuh7vaLE0UmAOwimaupgT2U5ISnET03X/pmjGdIKavvTaDnkWCZz/yoikue5WpRR1y/5Q1vPJaN89Yw…
selectors probed - google:
Certificate (current)
Amazon RSA 2048 M04
Expires in 280 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
same-origin- x-frame-options
DENY- permissions-policy
geolocation=*- x-content-type-options
nosniff- content-security-policy
script-src 'self' https://www.google.com/recaptcha/api.js https://www.gstatic.com https://www.clarity.ms https://*.larasuite.com https://prod.larasuite.com https://plataformadev.bvc.com.co/ https://plataformatest.bvc.com.co https://plataformacert.bvc.com.co https://www.google-analytics.com http://static.hotjar.com https://static.hotjar.com https://script.hotjar.com tagmanager.google.com googletagmanager.com www.googletagmanager.com stats.g.doubleclick.net 'unsafe-inline'; frame-ancestors https://www.kumo360.com https://youtube.com;- strict-transport-security
max-age=31536000; includeSubDomains; preload