gaes.es
HTML metadata
Technology
- Server
- Apache
Third-party hosts loaded (4)
- www.amplifon.com×11
- assets.adobedtm.com×1
- www.beterhoren.nl×1
- www.minisom.pt×1
Social
Contact
- Phone
DNS records live
- NS
-
- ns-1300.awsdns-34.org
- ns-1698.awsdns-20.co.uk
- ns-337.awsdns-42.com
- ns-616.awsdns-13.net
- MX
-
- 0 gaes-es.mail.protection.outlook.com
- TXT
-
Show 4 TXT records
6tt0lml57l8xw19tx5b387sdkx7qrc0kapple-domain-verification=pFDLHxVJ8nHlToAqxW-iZl2NQH0vyXnW2qsT0m2Sx_kdtm-domain-verification=_2tupV6Q34hNNLroOUOdj9q4HaDoiPkEVXd-1ZjQVOAspycloud-domain-verification=ec3cd2d7-7f22-414e-b17f-4a81225c835c
Email authentication strong
- SPF
-
v=spf1 include:spf.protection.outlook.com -allstrict (-all) - DMARC
-
v=DMARC1; p=quarantine; rua=mailto:dmarc@amplifon.compolicy: quarantine - DKIM
- no key found at common selectors
Certificate (current)
GeoTrust TLS RSA CA G1
Expires in 100 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- weak frame protection
- weak content type protection
- missing Permissions Policy
Header values
- referrer-policy
strict-origin-when-cross-origin, strict-origin-when-cross-origin- x-frame-options
DENY, DENY- x-content-type-options
nosniff, nosniff- content-security-policy
default-src 'self' 'unsafe-inline' antevenio.uinterbox.com *.adobedc.net *.arkeero.net *.outbrain.com *.zemanta.com *.taboola.com *.falcometric.com tibolario.com *.clarity.ms *.contentsquare.net *.yextevents.com *.sitescdn.com *.sitescdn.net *.keyxel.com *.tiktok.com *.trackads.eu *.teads.tv *.adnxs.com *.arkeero.net *.google-analytics.com *.adgoaffiliation-int.com *.adgoaffiliation.com *.entregarapida.es *.hotjar.com *.cookielaw.org *.googlesyndication.com gaes.es www.gaes.es https://fonts.googleapis.com; script-src 'self' 'unsafe-hashes' 'unsafe-inline' 'unsafe-eval' *.scene7.com *.g2afse.com antevenio.uinterbox.com *.adobedc.net *.arkeero.net *.zemanta.com *.falcometric.com tibolario.com *.clarity.ms app.contentsquare.com *.contentsquare.net *.sitescdn.com *.keyxel.com *.sitescdn.net *.yextevents.com *.tiktok.com *.trackads.eu *.teads.tv *.adnxs.com *.arkeero.net *.outbrain.com *.google-analytics.com *.adgoaffiliation-int.com *.adgoaffiliation.com *.entregarapida.es *.hotjar.com- strict-transport-security
max-age=31536000; includeSubDomains, max-age=31536000; includeSubDomains