discapzine.es
HTML metadata
Technology
- Server
- Apache
- CMS
- WordPress
- Analytics
-
- Google Tag Manager
- Fonts
-
- Google Fonts
Third-party hosts loaded (9)
- dxvw16p6pji3p.cloudfront.net×58
- secure.gravatar.com×4
- stats.wp.com×3
- fonts.googleapis.com×2
- www.googletagmanager.com×2
- www.gravatar.com×2
- revive.inidis.com×1
- wp.me×1
- www.facebook.com×1
Social
Contact
- Phone
DNS records live
- NS
-
- ns2.inidis.com
- ns3.inidis.com
- MX
-
- 10 correo.inidis.com
- 20 smtp.inidis.com
Email authentication weak
- SPF
-
v=spf1 a mx a:correo.inidis.com a:cm-staticIP-85-152-40-132.telecable.es a:cai.iniweb.es a:aws01.inidis.com a:ec2-54-75-241-63.eu-west-1.compute.amazonaws.com -allstrict (-all) - DMARC
- not published
- DKIM
-
- default:
v=DKIM1; r=postmaster; g=*; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDPRL1/N+4n8TKYt4jMiuGrA5uMg6xTWdX3J115gjynzYYi2NLG5ohrTLizbZKpOLa…
selectors probed - default:
Certificates
Loading certificate
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- findings
-
- CSP uses wildcard sources
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src 'self' https://app-directory.s3.amazonaws.com/hootlet/; connect-src 'self' data: https://region1.google-analytics.com/ https://discapzine.es https://yoast.com/feed/widget/ https://www.google-analytics.com/ https://stats.g.doubleclick.net/ https://cdn.plyr.io/; font-src 'self' data: https://discapzine.es https://cdn.discapzine.es/ https://dxvw16p6pji3p.cloudfront.net/ https://fonts.gstatic.com data: https://fonts.gstatic.com https://maxcdn.bootstrapcdn.com https://*.wp.com/ https://use.fontawesome.com/ https://d1lataq7vckovt.cloudfront.net/; child-src 'self' https://discapzine.es https://cdn.discapzine.es/ https://www.google.com https://www.youtube.com https://player.vimeo.com/ https://widgets.wp.com/ https://www.facebook.com/ https://*.twitter.com/; img-src 'self' data: https://discapzine.es https://cdn.discapzine.es/ https://www.google-analytics.com https://*.gravatar.com https://s.w.org https://maps.gstatic.com/ https://maps.googleapis.com/ https://pixel.wp.com/ https://- strict-transport-security
max-age=63072000; includeSubdomains; preload