compromisosocial.es
HTML metadata
Technology
- Server
- Web
- CMS
- WordPress
- Analytics
-
- Google Tag Manager
- Fonts
-
- Google Fonts
Third-party hosts loaded (2)
- fonts.googleapis.com×3
- www.googletagmanager.com×1
DNS records live
- NS
-
- holly.ns.cloudflare.com
- nash.ns.cloudflare.com
- TXT
-
Show 4 TXT records
google-site-verification=9EzzU4Fl7CUo3Z8HFQ80PK9oC82uCdQet0OHYU0JQNo_iikddctpk0n4bvmi1ew4h0j2l2wro7l_qitmgj9qsmwh21z7fso9v8ecfub913fg367zfq2qhxh4yb2ychv4gllzv86ywyv
Email authentication no MX
- SPF
-
v=spf1 -allstrict (-all) - DMARC
-
v=DMARC1; p=reject; sp=reject; fo=1; ri=3600; rua=bpyupkwi@ag.eu.dmarcadvisor.com; ruf=bpyupkwi@fr.eu.dmarcadvisor.com;policy: reject (enforced) · sp=reject - DKIM
- no key found at common selectors
Certificate (current)
GeoTrust TLS RSA CA G1
Expires in 228 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Permissions Policy
Header values
- referrer-policy
same-origin- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
child-src 'self' https://*.cookiebot.com/ https://www.youtube-nocookie.com https://www.google.com blob:; connect-src 'self' https://*.bemyvega.com https://*.bemyvega.dev https://*.google-analytics.com https://*.analytics.google.com https://*.cookiebot.com/ https://api.hubspot.com https://*.doubleclick.net; default-src 'self' https://fonts.cdnfonts.com; font-src 'self' data: https://fonts.gstatic.com; frame-ancestors 'self' https://compromisosocial.es; img-src 'self' data: https://track.hubspot.com https://*.analytics.google.com https://secure.gravatar.com https://s.w.org https://www.facebook.com https://www.google-analytics.com https://www.gstatic.com https://i.ytimg.com https://translate.google.com https://www.googletagmanager.com https://*.doubleclick.net https://www.google.es https://d3gv9rjgoevzzo.cloudfront.net https://access.nagich.com; object-src 'none'; style-src 'self' 'unsafe-inline' https://*.googleapis.com/ https://fonts.cdnfonts.com; base-uri 'none'; report-uri https://gru- strict-transport-security
max-age=63072000; includeSubDomains; preload