galeriadelascoleccionesreales.es

.es crawl

First seen 2026-04-11 · Last seen 2026-05-18 · ok HTTP/1.1 200 4547 ms crawled 2026-05-18

ES · 185.73.174.208 · AS200521 Ministerio de Transformacion Digital y de la Funcion Publica

Reputation 100/100

Classifying

HTML metadata

Title
Home - La Galería de las Colecciones Reales
Description
The new Patrimonio Nacional museum, located in the heart of Madrid next to the Royal Palace, brings together more than 700 works of art representative of five c...
Language
en
Canonical
https://www.galeriadelascoleccionesreales.es/en
Translations
  • en
  • es

Technology

Server
nginx
Fonts
  • Font Awesome
  • Google Fonts
Social widgets
  • Vimeo Embed
Third-party hosts loaded (10)
  • cdnjs.cloudflare.com×3
  • code.jquery.com×3
  • cdn.datatables.net×2
  • unpkg.com×2
  • cdn.jsdelivr.net×1
  • fonts.googleapis.com×1
  • player.vimeo.com×1
  • serviciospregcr.coleccionesreales.es×1
  • use.fontawesome.com×1
  • www.gstatic.com×1

Social

Contact

Phone
Address
C/ Bailén s/n, 28013

DNS records live

NS
  • ns1.age.gob.es
  • ns2.age.gob.es
Verified for
  • Google
  • HARICA

Email authentication no MX

SPF
not published
DMARC
not published
DKIM
no key found at common selectors

Certificate (current)

GEANT TLS RSA 1
from 2026-04-08 to 2026-10-24
Expires in 156 days

HTTP security headers

Header hygiene 85/100 Checked live page: https://www.galeriadelascoleccionesreales.es/en

present
  • strict-transport-security
  • content-security-policy
  • x-frame-options
  • x-content-type-options
  • referrer-policy
  • cross-origin-opener-policy
  • cross-origin-embedder-policy
findings
  • CSP allows unsafe inline scripts/styles
  • weak content type protection
  • missing Permissions Policy
Header values
referrer-policy
no-referrer-when-downgrade
x-frame-options
SAMEORIGIN
x-content-type-options
nosniff, nosniff
content-security-policy
default-src https: data: 'unsafe-inline' 'unsafe-eval'
strict-transport-security
max-age=31536000; includeSubDomains; preload, max-age=31536000; includeSubDomains
cross-origin-opener-policy
same-origin-allow-popups
cross-origin-embedder-policy
require-corp, credentialless

Links to (7)

Linked from (2)