domusvi.es
HTML metadata
Technology
- CDN
- Cloudflare
- CMS
- Nuxt
- Analytics
-
- Cloudflare Insights
- Google Tag Manager
- Fonts
-
- Google Fonts
Third-party hosts loaded (8)
- a.storyblok.com×31
- www.youtube.com×2
- challenges.cloudflare.com×1
- fonts.googleapis.com×1
- fonts.gstatic.com×1
- img.youtube.com×1
- static.cloudflareinsights.com×1
- www.googletagmanager.com×1
Social
Contact
- Phone
DNS records live
- NS
-
- ns-190-a.gandi.net
- ns-40-b.gandi.net
- ns-68-c.gandi.net
- MX
-
- 10 mx1.hc1074-82.eu.iphmx.com
- 10 mx2.hc1074-82.eu.iphmx.com
- TXT
-
Show 16 TXT records
MS=ms79079796SFMC-lA3sl7Dn7hfXRcrOb0ESUpy8LZ__UJr4huQIr33Dcitrix.mobile.ads.otp=qt0g7g5nx37v5rcogsi7brevo-code:b6dd0cada805753991d02012f45575ecglobalsign-domain-verification=A08C47D522629B1C6E2507B4E359F16C7je9j323h274qfqi1376pk164kgoogle-site-verification=3_TzdG0PwMQL8cyuF8f7EmH3GkBIrfISt1PepPLR1KUs9uep6b2b2stl794918fnsohhf7o64upfdb3uqolp8fdlr7ebrun6o9vun7udc21dqmsfvgpg090o6p8k4rn2t5rnam9e8hl12omc6f4google-site-verification=BFhYL4iIojrslU_aKszhpMf6nr5rEUxFH74LJRmsvxcgoogle-gws-recovery-domain-verification=52764437euoqrivj13e9cps3ds1i6chhhae50kkcesu872qv0n5eg1e0dednapple-domain-verification=84miO9awMn6nJb1B
Email authentication strong
- SPF
-
v=spf1 mx ip4:213.41.35.102/32 ip4:207.54.69.97/32 ip4:23.90.116.112/32 ip4:207.54.72.12/32 ip4:23.90.116.115/32 ip4:23.249.220.134/32 ip4:23.249.220.135/32 include:spf.protection.outlook.com include:spf.brevo.com -allstrict (-all) - DMARC
-
v=DMARC1; p=reject; ruf=mailto:dmarc_spoofing@domusvi.es;rua=mailto:dmarc_spoofing@domusvi.es; aspf=r; adkim=s; ri=3600policy: reject (enforced) - DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAuKBBgsW87+oPbYvIlgXbRoxuOdhVjOoHgyHxG2p4/6aFj/K1SC/8P5L/CrmokqfEBhuSHyoe9lcG41… - selector2:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAxDQiOiGLoWx/2+FKvEaEthACPGP/J3uiOA42F5oyUWWB55j0/XcN4WIS6/MlYbox3RlLbg/35C6h8B… - s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAs9qmkBHM3ERIJS4fk4hREEhUkPvoPBC8WAn/4vObkCar7gZDDImbh4oBEb01nXBK3+H5w1rBhGpxt2HHWK… - s2:
k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQC6iUypGeo/bxeKG7YRQ656cNfeBkCWNEuLLz2cXsjxRZ3NsY5aE/ZvJJ5RX2ITY2JAsfl6x1TaFBp2UL4/BKDHRw…
selectors probed - selector1:
Certificate (current)
Gandi RSA Domain Validation Secure Server CA 3
Expires in 146 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- cross-origin-opener-policy
- cross-origin-resource-policy
- findings
-
- CSP allows unsafe inline scripts/styles
Header values
- referrer-policy
no-referrer- x-frame-options
SAMEORIGIN- permissions-policy
camera=(), display-capture=(), fullscreen=(), geolocation=(self), microphone=()- x-content-type-options
nosniff- content-security-policy
base-uri 'self'; font-src 'self' https: data:; form-action 'self'; frame-ancestors self https:; img-src 'self' data: https:; object-src 'none'; script-src-attr 'none'; style-src 'self' https: 'unsafe-inline'; upgrade-insecure-requests- strict-transport-security
max-age=15552000; includeSubDomains- cross-origin-opener-policy
same-origin- cross-origin-resource-policy
same-origin