gestagua.es
HTML metadata
Technology
- Server
- nginx
- CMS
- WordPress
- Fonts
-
- Google Fonts
Third-party hosts loaded (3)
- cdn.jsdelivr.net×3
- fonts.googleapis.com×2
- fonts.gstatic.com×2
Social
Contact
DNS records live
- NS
-
- ns85.dioxinet.com
- ns88.dioxinet.com
- MX
-
- 0 mxa-004e8701.gslb.pphosted.com
- 0 mxb-004e8701.gslb.pphosted.com
- TXT
-
Show 14 TXT records
MS=ms73031414b7839187-0146-435e-9048-e1dd3b7d3347google-site-verification=6LgiIkBxgEOpef9yt8KfSRS8oQht8_2ngSbsFD7b3dI"20230221104618329i68vd0zazrbgkthk2mfghvne5lz7ew3bmsvnxvi0k9yxse3"v=spf1 include:spf-004e8701.pphosted.com include:spf.protection.outlook.com -alldocusign=a00c28e1-f7a3-4a78-b7df-8db1a05ba6ffMS=ms8843541464339743-9c5b-42d9-8653-857c53ab4b90202501271037104jp4twy91tz3ljzb7fzmjpdo04thbufzz0wza1iiepfugdh01v"91b34f96-f1c8-49ff-b012-7b3bea9b9977"docusign=e83e2fd0-7e45-475f-8b46-8dfcb6a19f43apple-domain-verification=sj1s7A61M88QGYjT202402090730404c5zfod93xgvbeiqkfhbizcfb5qlkjgy6ntb381k4ilxa4pjs9JCFnFM5aRGrGnvFvikZcDVBYDVN0+zdJPww98L3ZO5yQkDaPTSgCuLk+3u8k+qp80yugAt486pB005/in7iLjA==
Email authentication partial
- SPF
-
v=spf1 include:spf-004e8701.pphosted.com include:spf.protection.outlook.com -allstrict (-all) - DMARC
-
v=DMARC1;p=none; fo=1;rua=mailto:dmarc_rua@emaildefense.proofpoint.com; ruf=mailto:dmarc_ruf@emaildefense.proofpoint.compolicy: none (monitoring only) - DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA5v/MzFf+tc8ytwEIrjz6p4Umq6UAvuxgcZcdWMRgLX6HvjfULGFbJjCggJbYP/Tq2Vjk15tb6WtB4u… - selector2:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEArGXyd/C3vYWakP1iMvkzCX5jwP4S7mTj9vJa5t8zN8U2IqSERBktKBvJKCQIQnEy8U+kQO9A2bscEb… - s1:
v=DKIM1; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAr+1dpfy1JXcpuj9iX/I0aTmXy6WvDOCn3cl9D8OltkdBBu3ORznmBHtoLsF+Ott8JUg25nD/eqdA/zrf2qisj…
selectors probed - selector1:
Certificate (current)
Sectigo Public Server Authentication CA EV R36
Expires in 86 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- missing frame protection
Header values
- referrer-policy
strict-origin-when-cross-origin- permissions-policy
camera=(), microphone=(), geolocation=(), fullscreen=(), payment=()- x-content-type-options
nosniff- content-security-policy
default-src 'self' https://www.youtube.com; script-src 'self' https://ajax.googleapis.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://maps.googleapis.com https://www.google-analytics.com https://1millionbot.com https://gestagua.es https://www.gestagua.es 'unsafe-inline' 'unsafe-eval'; style-src 'self' https://fonts.googleapis.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com 'unsafe-inline'; font-src 'self' https://gestagua.es https://fonts.gstatic.com https://www.gestagua.es data:; img-src 'self' https://www.gestagua.es https://gestagua.es https://secure.gravatar.com data:; connect-src 'self' https://maps.googleapis.com https://yoast.com; object-src 'none'; base-uri 'self'; frame-ancestors 'self'; worker-src 'self' blob:;- strict-transport-security
max-age=31536000; includeSubDomains