cajamarinnova.es
HTML metadata
Technology
- Server
- Web
- CMS
- WordPress
- Analytics
-
- Google Tag Manager
- Fonts
-
- Google Fonts
Third-party hosts loaded (2)
- fonts.googleapis.com×4
- www.googletagmanager.com×1
Social
DNS records live
- NS
-
- holly.ns.cloudflare.com
- nash.ns.cloudflare.com
- TXT
-
_equf607myyo5wp0p0bk2oq37av935o0_q5sbbyklj3q3c7mapswtdysa2sg6wbi
- Verified for
-
Email authentication no MX
- SPF
-
v=spf1 -allstrict (-all) - DMARC
-
v=DMARC1; p=reject; sp=reject; fo=1; ri=3600; rua=bpyupkwi@ag.eu.dmarcadvisor.com; ruf=bpyupkwi@fr.eu.dmarcadvisor.com;policy: reject (enforced) · sp=reject - DKIM
- no key found at common selectors
Certificate (current)
Thawte TLS RSA CA G1
Expires in 183 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-content-type-options
- referrer-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing frame protection
- missing Permissions Policy
Header values
- referrer-policy
same-origin- x-content-type-options
nosniff- content-security-policy
child-src 'self' https://*.cookiebot.com/ https://www.youtube-nocookie.com https://www.google.com; connect-src 'self' https://*.bemyvega.com https://*.bemyvega.dev https://analytics.google.com https://www.google.es https://*.google-analytics.com https://*.analytics.google.com https://*.cookiebot.com/ https://api.hubspot.com https://stats.g.doubleclick.net; default-src 'self' https://fonts.cdnfonts.com; font-src 'self' data: https://fonts.gstatic.com; frame-ancestors 'self' https://compromisosocial.es; img-src 'self' data: https://track.hubspot.com https://d3gv9rjgoevzzo.cloudfront.net https://access.nagich.com https://*.analytics.google.com https://secure.gravatar.com https://s.w.org https://www.facebook.com https://www.google-analytics.com https://www.gstatic.com https://i.ytimg.com https://translate.google.com https://www.googletagmanager.com https://www.google.es https://stats.g.doubleclick.net https://*.cookiebot.com; object-src 'none'; style-src 'self' 'unsafe-inline' https://fon- strict-transport-security
max-age=63072000; includeSubDomains; preload