dekra.es
HTML metadata
Technology
- CMS
- Nuxt
Third-party hosts loaded (30)
- dekraprod-media.e-spirit.cloud×35
- www.dekra.com.cn×3
- www.dekra.be×2
- www.dekra.co.jp×2
- www.dekra.com.tw×2
- www.dekra.fi×2
- www.dekra.kr×2
- www.dekra.lu×2
- www.dekra.mx×2
- www.dekra.nl×2
- www.dekra.se×2
- www.dekra.us×2
- www.dekra-uk.co.uk×1
- www.dekra.at×1
- www.dekra.cl×1
- www.dekra.com×1
- www.dekra.com.br×1
- www.dekra.cr×1
- www.dekra.de×1
- www.dekra.hr×1
- www.dekra.hu×1
- www.dekra.in×1
- www.dekra.it×1
- www.dekra.ma×1
- www.dekra.pl×1
- www.dekra.pt×1
- www.dekra.ro×1
- www.dekra.rs×1
- www.dekra.sk×1
- www.dekra.ua×1
Social
DNS records live
- NS
-
- dns5.servidoresdns.net
- dns6.servidoresdns.net
- MX
-
- 10 mx.serviciodecorreo.es
- TXT
-
btckqcgihrf1vjh85vess65c8u
Email authentication weak
- SPF
-
v=spf1 include:_spf.serviciodecorreo.es -allstrict (-all) - DMARC
- not published
- DKIM
- no key found at common selectors
Certificate (current)
Go Daddy Secure Certificate Authority - G2
Expires in 17 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- cross-origin-resource-policy
- findings
-
- CSP uses wildcard sources
- missing Permissions Policy
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
base-uri 'self'; connect-src 'self' blob: data: https://*.applicationinsights.azure.com https://js.monitor.azure.com https://matomo.dekra.bawue.com https://*.clarity.ms https://c.bing.com https://*.g.doubleclick.net https://dekra-dev-search-api.e-spirit.cloud https://dekra-search-api.e-spirit.cloud https://*.google.ad https://*.google.ae https://*.google.al https://*.google.am https://*.google.as https://*.google.at https://*.google.az https://*.google.ba https://*.google.be https://*.google.bf https://*.google.bg https://*.google.bi https://*.google.bj https://*.google.bs https://*.google.bt https://*.google.by https://*.google.ca https://*.google.cat https://*.google.cd https://*.google.cf https://*.google.cg https://*.google.ch https://*.google.ci https://*.google.cl https://*.google.cm https://*.google.cn https://*.google.co.ao https://*.google.co.bw https://*.google.co.ck https://*.google.co.cr https://*.google.co.id https://*.google.co.il https://*.google.co.in https://*.google.c- strict-transport-security
max-age=31536000; includeSubDomains- cross-origin-resource-policy
cross-origin