canal180.pt

.pt crawl

First seen 2026-05-14 · Last seen 2026-05-19 · ok HTTP/1.1 200 5681 ms crawled 2026-05-19

DE · 157.245.27.75 · AS14061 DigitalOcean, LLC

Reputation 92/100 no dmarc policy

Classifying

HTML metadata

Title
Canal180
Description
Canal180 celebrates uniqueness and voice diversity by producing inspiring experimental audiovisual content about both pioneering and emerging creators.
Language
en
Canonical
https://www.canal180.pt/
Translations
  • en
  • pt

Open Graph

url
https://www.canal180.pt/
title
Canal180
description
Canal180 celebrates uniqueness and voice diversity by producing inspiring experimental audiovisual content about both pioneering and emerging creators.

Technology

CDN
Cloudflare
Server
openresty
Analytics
  • Google Analytics
  • Google Tag Manager
Ads
  • Meta Pixel
Fonts
  • Google Fonts

Third-party hosts loaded (6)

  • img.bndlyr.com×9
  • cdn.bndlyr.com×8
  • www.googletagmanager.com×2
  • connect.facebook.net×1
  • fonts.gstatic.com×1
  • www.google-analytics.com×1

Social

DNS records live

NS
  • ns1.linode.com
  • ns2.linode.com
  • ns3.linode.com
  • ns4.linode.com
  • ns5.linode.com
MX
  • 10 mx.zoho.com
  • 20 mx2.zoho.com
  • 30 mx3.zoho.com
Verified for
  • Zoho

Email authentication weak

SPF
v=spf1 include:zoho.com ~all
softfail (~all)
DMARC
not published
DKIM
no key found at common selectors

Certificate (current)

R12
from 2026-05-15 to 2026-08-13
Expires in 85 days

HTTP security headers

Header hygiene 90/100 Checked live page: https://www.canal180.pt/

present
  • strict-transport-security
  • content-security-policy
  • x-frame-options
  • x-content-type-options
  • referrer-policy
  • permissions-policy
findings
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
Header values
referrer-policy
strict-origin-when-cross-origin
x-frame-options
SAMEORIGIN
permissions-policy
geolocation=(self),microphone=(self),camera=(self),autoplay=(self),picture-in-picture=(self)
x-content-type-options
nosniff
content-security-policy
manifest-src *; default-src 'self' blob:; media-src * data: blob:; frame-ancestors 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https: blob: data:; img-src * 'self' data: blob: https:; style-src 'self' 'unsafe-inline' https:; font-src 'self' data: https:; frame-src *; connect-src https: wss:; object-src 'none'
strict-transport-security
max-age=63072000; includeSubDomains; preload

Links to (9)

Linked from (4)