caritaspamplona.org

.org crawl

First seen 2026-06-02 · Last seen 2026-06-03 · ok HTTP/1.1 200 1491 ms crawled 2026-06-03

FR · 51.38.181.17 · AS16276 OVH SAS

Reputation 92/100 weak subdomain policy

Classifying

HTML metadata

Title
Cáritas Diocesana de Pamplona y Tudela (Navarra)
Language
es-ES
Generator
WordPress 6.8.5
Canonical
https://www.caritaspamplona.org/
Translations
  • en
  • es
  • eu
  • fr
Feeds

Technology

Server
Apache
CMS
WordPress 6.8.5
jQuery
3.7.1

Third-party hosts loaded (2)

  • gmpg.org×1
  • maps.google.com×1

Social

Contact

Email
Phone

Registration

Registrar
CSL Computer Service Langenbach GmbH d/b/a joker.com
Created
2000-05-16
Expires
2027-05-16 344 days left
Updated
2026-05-14
Name servers
  • x.ns.joker.com
  • y.ns.joker.com
  • z.ns.joker.com

DNS records live

NS
  • x.ns.joker.com
  • y.ns.joker.com
  • z.ns.joker.com
MX
  • 20 caritaspamplona-org.mail.protection.outlook.com

Email authentication strong

SPF
v=spf1 mx a:ares.nsoluciones.com include:spf.protection.outlook.com a:caritaspamplona.com -all
strict (-all)
DMARC
v=DMARC1; p=quarantine; sp=none;
policy: quarantine · sp=none
DKIM
  • default: v=DKIM1; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAo7/7BSSBUCHoQHCYjVl8/+Ap9S/66kWoQjXiKxrd3GC8lorZNPa2gkEbtlhi7ENxJ+OWnmnpY1jAabT+…
selectors probed

Certificate (current)

E7
from 2026-04-09 to 2026-07-08
Expires in 32 days

HTTP security headers

Header hygiene 90/100 Checked live page: https://www.caritaspamplona.org/

present
  • strict-transport-security
  • content-security-policy
  • x-frame-options
  • x-content-type-options
  • referrer-policy
  • permissions-policy
findings
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
Header values
referrer-policy
strict-origin-when-cross-origin
x-frame-options
SAMEORIGIN
permissions-policy
geolocation=(), camera=(), microphone=(), fullscreen=(self), payment=()
x-content-type-options
nosniff
content-security-policy
default-src 'self' https:; script-src 'self' 'unsafe-inline' 'unsafe-eval' https:; style-src 'self' 'unsafe-inline' https:; img-src 'self' data: https: *; font-src 'self' https:;
strict-transport-security
max-age=31536000; includeSubDomains

Links to (2)

Linked from (1)