dannregional.com.co
HTML metadata
Technology
- CDN
- Amazon CloudFront
- Server
- Iris
Third-party hosts loaded (1)
- cl00041-irissite-static-pdn-s3.s3.amazonaws.com×1
DNS records live
- NS
-
- ns-1363.awsdns-42.org
- ns-1798.awsdns-32.co.uk
- ns-262.awsdns-32.com
- ns-726.awsdns-26.net
- MX
-
- 1 aspmx.l.google.com
- 10 alt3.aspmx.l.google.com
- 10 alt4.aspmx.l.google.com
- 5 alt1.aspmx.l.google.com
- 5 alt2.aspmx.l.google.com
- TXT
-
_8osaq3abe4obww9hcxh77o3apxg2t8w4w509sf6jq292mhrgttzcj8f3tmftxj2
Email authentication strong
- SPF
-
v=spf1 ip4:190.145.230.210 include:_spf.google.com include:senders.imolko.com include:zcsend.net include:spf.zoho.com include:transmail.net ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=quarantine; pct=100; rua=mailto:infraestructura@dannregional.com.copolicy: quarantine - DKIM
-
- google:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDeRGZhGuYt2UJ4cvvfLRjSXaukLmzPEw1iIXkNUvnJQDc0CjYnPDieKrFzRf5Pf3SoB8x9UIoSBmt0JZfQKF…
selectors probed - google:
Certificate (current)
Amazon RSA 2048 M01
Expires in 142 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Permissions Policy
Header values
- referrer-policy
same-origin- x-frame-options
DENY- x-content-type-options
nosniff- content-security-policy
default-src 'self'; style-src 'self' fonts.googleapis.com fonts.gstatic.com cdn.jsdelivr.net www.gstatic.com *.s3.amazonaws.com 'unsafe-inline'; font-src 'self' fonts.googleapis.com fonts.gstatic.com v2.zopim.com *.s3.amazonaws.com 'unsafe-inline' data:; img-src * 'self' data: https:; connect-src 'self' *.dannregional.com.co wss://*.dannregional.com.co graph.facebook.com ekr.zdassets.com wss://widget-mediator.zopim.com *.amazonaws.com wss://*.amazonaws.com *.twilio.com wss://*.twilio.com analytics.google.com www.google-analytics.com *.getmati.com wss://*.getmati.com stats.g.doubleclick.net desk.zoho.com iriscfcompaadefinanciamientosa.zendesk.com static.iris.com.co *.irsbnk.co *.irisbank.co static.iris.com.co wss://static.iris.com.co *.hotjar.com wss://*.hotjar.com *.hotjar.io wss://*.hotjar.io; script-src 'self' *.hotjar.com *.metamap.com static.iris.com.co *.hotjar.com static.hotjar.io *.hotjar.io static.hotjar.com *.facebook.com googleads.g.doubleclick.net www.googleadservices.com w- strict-transport-security
max-age=63072000; includeSubdomains; preload