cores.es

.es crawl

First seen 2026-04-21 · Last seen 2026-05-14 · ok HTTP/1.1 200 1729 ms crawled 2026-05-14

ES · 94.143.138.137 · AS8560 IONOS SE

Reputation 92/100 no dmarc policy

sector government type homepage

HTML metadata

Title
CORES
Description
CORES, Entidad Central de Almacenamiento en España, contribuye a garantizar la seguridad de suministro de productos petrolíferos, GLP y gas natural en España, y es referente de información de hidrocarburos
Language
es
Canonical
https://www.cores.es/es

Technology

Server
nginx
CMS
Drupal
Analytics
  • Google Tag Manager

Third-party hosts loaded (2)

  • www.googletagmanager.com×4
  • cdn.jsdelivr.net×1

Social

Contact

Phone

DNS records live

NS
  • ns10.servicio-online.net
  • ns11.servicio-online.net
  • ns12.servicio-online.net
MX
  • 10 cores-es-1.fortimailcloud.com
  • 20 cores-es-2.fortimailcloud.com
TXT
  • _av34wi1ls982e90g8dz239pleqy58v2
  • qwm60lm8nmp85b5nv3jxyp6ld4wzrh14
  • apple-domain-verification=A6kWAHmG1exjwITY

Email authentication weak

SPF
v=spf1 include:spf.protection.outlook.com include:_spf.fortimailcloud.com -all
strict (-all)
DMARC
not published
DKIM
  • selector1: v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDeKbg5mzcDvOcg9L2/PVxnl3Uwrr6nw9qblfhLfFN1/6lWy5N5/Kfin3maDSSAa0HoVEB5zjr0gSoPAaLftF…
  • selector2: v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAzRQUfU2pYyg1ZDV6s/njaISs6WBoNlOsQ3BWfS38j3H+ZU1oIl1pHrhvAMrd0fQmaAcQGn1eiQp9OX…
  • k1: k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDbNrX2cY/GUKIFx2G/1I00ftdAj713WP9AQ1xir85i89sA2guU0ta4UX1Xzm06XIU6iBP41VwmPwBGRNofhBVR+e6WHUo…
selectors probed

Certificate (current)

R13
from 2026-04-02 to 2026-07-01
Expires in 42 days

HTTP security headers

Header hygiene 90/100 Checked live page: https://www.cores.es/

present
  • strict-transport-security
  • content-security-policy
  • x-frame-options
  • x-content-type-options
  • referrer-policy
  • permissions-policy
findings
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
Header values
referrer-policy
no-referrer-when-downgrade
x-frame-options
SAMEORIGIN
permissions-policy
geolocation=(), microphone=(), camera=(), fullscreen=(), payment=()
x-content-type-options
nosniff
content-security-policy
default-src 'none'; script-src 'self' 'unsafe-inline' 'unsafe-hashes' 'unsafe-eval' *.google-analytics.com *.google.com *.gstatic.com https://www.googletagmanager.com https://kit.fontawesome.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://unpkg.com; object-src 'self'; style-src 'self' 'unsafe-hashes' 'unsafe-inline' https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://www.gstatic.com https://fonts.googleapis.com; img-src 'self' https://www.google-analytics.com https://www.gstatic.com https://www.googletagmanager.com https://region1.google-analytics.com https://cdn.jsdelivr.net https://translate.google.com https://fonts.gstatic.com data:; media-src 'self'; frame-src 'self' *.google.com; frame-ancestors 'self'; child-src 'self'; font-src 'self' https://ka-f.fontawesome.com https://fonts.gstatic.com data:; connect-src 'self' *.google-analytics.com https://ka-f.fontawesome.com; report-uri /report-csp-violation
strict-transport-security
max-age=31536000; includeSubDomains; preload

Links to (4)

Linked from (1)