fundela.es
HTML metadata
Technology
- Server
- Microsoft-IIS
- CMS
- Joomla
- Social widgets
-
- YouTube Embed
Third-party hosts loaded (1)
- www.youtube-nocookie.com×2
Social
DNS records live
- NS
-
- ns1.fundela.es
- ns2.fundela.es
- MX
-
- 10 mail.fundela.es
- 50 mailserver.inxenio.com
- 50 mx04.inxenio.com
- 50 mx05.inxenio.com
- TXT
-
google-site-verification=VKj_GNq2-DswqZFDvT35-tks_r8e1oozfru2USa7mJo
Email authentication partial
- SPF
-
v=spf1 +a +mx +cname +a:ns.rexistra.net -allstrict (-all) - DMARC
-
v=DMARC1; p=nonepolicy: none (monitoring only) - DKIM
-
- s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA0BcnLWA9MoYDVf+jwjBo6gsmH2O9Ubn3c8p4Z/qB0BzgkY4dJt+RhcgxfQVpgpE8SW/tFQ1wDcxI4ZDbCr… - s2:
k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDClM5f4pJ7P7rLQy20tgUtfFr2jwZKbU+0/XXkjSNOhdOX0gG//aHQfFRZf2yZwn3WLXK9gEjB/F4/oAGRspdW7v…
selectors probed - s1:
Certificate (current)
R12
Expires in 83 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Permissions Policy
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src 'self'; script-src 'unsafe-inline' 'self' 'unsafe-eval' https://www.youtube.com https://s.ytimg.com https://js.stripe.com/ www.google-analytics.com ajax.googleapis.com www.googletagmanager.com s7.addthis.com connect.facebook.net code.jquery.com https://code.s4d.io https://*.typeform.com https://*.google.com https://www.gstatic.com https://*.gstatic.com https://e.issuu.com https://secure.geonames.org https://cdn.amcharts.com https://cdn.jsdelivr.net/ https://unpkg.com https://*.insuit.net https://maps.googleapis.com; connect-src 'self' https://www.youtube.com https://*.youtube.com https://*.googlevideo.com https://sentry.issuu.com *.google-analytics.com *.googleapis.com www.googletagmanager.com s7.addthis.com connect.facebook.net localhost ws://localhost:8000 wss://*.ciscospark.com wss://*.wbx.com wss://*.wbx2.com https://*.ciscospark.com https://*.clouddrive.com/ https://code.s4d.io https://*.giphy.com https://*.wbx2.com https://*.webex.com https://*.webexcontent.com https:- strict-transport-security
max-age=63072000