catatu.es
HTML metadata
Technology
- Server
- HTTPd
- Analytics
-
- Google Tag Manager
- Ads
-
- Meta Pixel
Third-party hosts loaded (4)
- ajax.googleapis.com×3
- www.googletagmanager.com×2
- connect.facebook.net×1
- www.facebook.com×1
Social
Contact
- Phone
DNS records live
- NS
-
- ns.dinahosting.com
- ns2.dinahosting.com
- ns3.dinahosting.com
- ns4.dinahosting.com
- MX
-
- 10 aspmx.l.google.com
- 20 alt1.aspmx.l.google.com
- 30 alt2.aspmx.l.google.com
- 40 alt3.aspmx.l.google.com
- 50 alt4.aspmx.l.google.com
Email authentication strong
- SPF
-
v=spf1 ip4:82.98.181.71 include:_spf.google.com include:_spf.freshsales.io include:servers.mcsv.net ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=quarantine; rua=mailto:javier@catatu.es; ruf=mailto:javier@catatu.es; sp=none; ri=1728000; aspf=rpolicy: quarantine · sp=none - DKIM
-
- default:
v=DKIM1; g=*; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDWcfjoRZysGa5Bc2Qwy1AwQ2c1CYdaGvhWyhwaiWPuXQFkNO0aFa8iiN37+FeHLpbo4r2ztQu76vfNc… - google:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCXXWs8mVl6GlW5TxSoFUJgrh95L4hRMT1iZhIZCLCRWELWCJYDvi8gHJuPAXN9BCjo2Jfqk6PNmHDcRcRMmZ… - k2:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAv2aC2KjGKLOwTweBY5A9RpjsxaBXR9r7OAU6U8/zn92ivImI75naUujWbItRI/QmL1jy5PWGqLwoUA…
selectors probed - default:
Certificate (current)
R13
Expires in 37 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src 'self' 'unsafe-inline' https://use.fontawesome.com/releases/v5.6.3/css/all.css https://onesignal.com https://fonts.googleapis.com; font-src 'self' 'unsafe-inline' data: https://fonts.gstatic.com https://use.fontawesome.com; connect-src 'self' 'unsafe-inline' https://yoast.com https://onesignal.com https://www.facebook.com https://cdn.ampproject.org https://stats.g.doubleclick.net https://www.google-analytics.com https://www.googletagmanager.com/ https://ampcid.google.com https://ampcid.google.es; frame-src 'self' 'unsafe-inline' data: https://*.google.com https://www.facebook.com/; img-src 'self' https: data:; script-src 'self' 'unsafe-inline' 'unsafe-eval' data: blob: https://onesignal.com https://*.onesignal.com https://cdn.jsdelivr.net https://static.ads-twitter.com https://googleads.g.doubleclick.net https://www.google-analytics.com https://connect.facebook.net https://cdn.ampproject.org/v0/amp-form-latest.js https://cdn.ampproject.org/v0/amp-analytics-latest.js https:/- strict-transport-security
max-age=63072000; includeSubDomains
Links to (4)
- facebook.com×2
- twitter.com×2
- wa.me×2
- youtube.com×2