ebanca.com

.com crawl

First seen 2026-04-11 · Last seen 2026-05-18 · ok HTTP/1.1 200 1689 ms crawled 2026-05-18

US · 45.60.251.99 · AS19551 Incapsula Inc

Reputation 100/100

Classifying

HTML metadata

Title
Bancoagrícola
Language
es

Technology

CMS
Gatsby

Third-party hosts loaded (1)

  • resources.digital-cloud-west.medallia.com×1

Registration

Registrar
GoDaddy.com, LLC
Created
2004-05-09
Expires
2027-05-09 354 days left
Updated
2026-05-06
Name servers
  • proxy.bancoagricola.com
  • websvr.bancoagricola.com

DNS records live

NS
  • proxy.bancoagricola.com
  • websvr.bancoagricola.com
TXT
Show 4 TXT records
  • _kbdp1fjq4c8z3iu1iukmb68ct5z4k26
  • nsdqmtr3lfvtx97btcvnn5tlgngc1vzs
  • gr67md915lcckk3qxt0yy2g4q6hjyccr
  • d6n43g9g9vflktnxrnzgf1qpc4rnn5hl

Email authentication no MX

SPF
v=spf1 exists:%{i}._i.%{d}._d.espf.agari-dns.net include:%{d}.23.spf-protect.agari-dns.net -all
strict (-all)
DMARC
v=DMARC1; p=reject; fo=1; ri=86400; rua=mailto:bancolombia@rua.agari.com; ruf=mailto:bancolombia@ruf.agari.com,mailto:dmarc@bancolombia.com.co
policy: reject (enforced)
DKIM
no key found at common selectors

Certificate (current)

GeoTrust EV RSA CA G2
from 2025-06-28 to 2026-07-02
Expires in 43 days

HTTP security headers

Header hygiene 80/100 Checked live page: https://ebanca.com/

present
  • strict-transport-security
  • content-security-policy
  • x-frame-options
  • x-content-type-options
findings
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
  • missing Referrer Policy
  • missing Permissions Policy
Header values
x-frame-options
SAMEORIGIN
x-content-type-options
nosniff
content-security-policy
default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://*.digital-cloud-west.medallia.com https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://ebpcomport.bancoagricola.com; frame-src https://*.digital-cloud-west.medallia.com https://www.google.com/recaptcha/ https://recaptcha.google.com/recaptcha/; style-src 'self' 'unsafe-inline'; img-src 'self' blob: data: https://www.google-analytics.com; connect-src 'self' https://ebpcomport.bancoagricola.com https://*.digital-cloud-west.medallia.com; block-all-mixed-content; frame-ancestors 'self' https://backofficems.banagricola.com
strict-transport-security
max-age=31536000; includeSubDomains

Linked from (1)