fmirobcn.org
HTML metadata
Technology
- CDN
- Cloudflare
- Social widgets
-
- YouTube Embed
Third-party hosts loaded (4)
- cdn.jsdelivr.net×1
- cdn.userway.org×1
- tiqets-cdn.s3.amazonaws.com×1
- www.youtube-nocookie.com×1
Social
Contact
- Address
- Parc de Montjuïc
Registration
- Registrar
- 10dencehispahard SLU
- Created
- 2014-11-13
- Expires
- 2026-11-13 178 days left
- Updated
- 2025-11-04
- Name servers
-
- alberto.ns.cloudflare.com
- ingrid.ns.cloudflare.com
DNS records live
- NS
-
- alberto.ns.cloudflare.com
- ingrid.ns.cloudflare.com
- MX
-
- 10 mx01.hornetsecurity.com
- 20 mx02.hornetsecurity.com
- 30 mx03.hornetsecurity.com
- 40 mx04.hornetsecurity.com
- TXT
-
Show 6 TXT records
MS=5FE2421C4E8CD51AFED29EF005B50EABDAC40D5Dasv=5c06497d18285a451206f92d2c050d9eatlassian-domain-verification=ESyrtBJTN5F/cxcABr0H4i5sBdT0nXA3GsaTOAPNVolJWvKOjjze6dFSaakiulfggoogle-site-verification=BMgDFFkgq-glad6oDzWq6z29pq21uQaIQ65n3aNmAe8google-site-verification=PDLZZzsgJ6Grqtp86MxaaZaaRdFfRxPTobK72D-R5dMD2H4RHFECGSRN763QIVHVROML6
Email authentication partial
- SPF
-
v=spf1 include:spf.protection.outlook.com include:spf.hornetsecurity.com include:spf.mandrillapp.com include:_spf.srv.cat ip4:91.126.32.242 ip4:82.98.168.213 ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=none; sp=rejectpolicy: none (monitoring only) · sp=reject - DKIM
-
Show 4 DKIM selectors
- default:
v=DKIM1; g=*; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQC//VNioGNI6BuIpXt1DcHT5mIHyWwHOqhtVT9BLvOd9Qhib+4SBuXdROwXEAjnCF8APMrZbNo1C584H… - selector1:
v=DKIM1; k=rsa;p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAtlzn7iziF8hGzCdY4O69z/L497FjrLI875rwh3RZ1IsmigJ/2W6QueExu6iHheDndCa8bFPf6awop61… - selector2:
v=DKIM1; k=rsa;p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAtlzn7iziF8hGzCdY4O69z/L497FjrLI875rwh3RZ1IsmigJ/2W6QueExu6iHheDndCa8bFPf6awop61… - k2:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAv2aC2KjGKLOwTweBY5A9RpjsxaBXR9r7OAU6U8/zn92ivImI75naUujWbItRI/QmL1jy5PWGqLwoUA…
selectors probed - default:
Certificate (current)
WE1
Expires in 64 days
HTTP security headers
- present
-
- content-security-policy
- findings
-
- missing HSTS
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing frame protection
- missing content type protection
- missing Referrer Policy
- missing Permissions Policy
Header values
- content-security-policy
default-src 'self' data: 'unsafe-inline' 'unsafe-eval' *.userway.org *.stape.cc *.amazon *.amazon-adsystem.com *.adnxs.com *.google-analytics.com *.googleadservices.com *.googletagmanager.com *.youtube-nocookie.com *.youtube.com *.googleapis.com *.gstatic.com *.google.com *.google.es *.facebook.net *.facebook.com *.doubleclick.net tiqets-cdn.s3.amazonaws.com *.tiqets.com *.cloudflareinsights.com *.fmirobcn.org *.vimeo.com *.cloudflare.com *.cookiebot.com *.licdn.com *.googlesyndication.com *.linkedin.com *.clarity.ms analytics.tiktok.com *.jsdelivr.net;
Links to (7)
- linkedin.com×2
- spotify.com×2
- tiktok.com×2
- tiqets.com×2
- youtube.com×2
- facebook.com×2
- instagram.com×2