hispasat.com
HTML metadata
Technology
- Server
- Apache
- Analytics
-
- Google Tag Manager
Third-party hosts loaded (2)
- cdn.jsdelivr.net×3
- www.googletagmanager.com×1
Social
Registration
- Registrar
- Tucows Domains Inc.
- Created
- 1997-12-05
- Expires
- 2026-12-04 198 days left
- Updated
- 2025-11-05
- Name servers
-
- ns10.everex.es
- ns11.everex.es
- ns12.everex.es
- ns13.everex.es
- ns14.everex.es
DNS records live
- NS
-
- ns-1388.awsdns-45.org
- ns-1967.awsdns-53.co.uk
- ns-546.awsdns-04.net
- ns-78.awsdns-09.com
- MX
-
- 1 hispasat-com.mail.protection.outlook.com
- TXT
-
Show 14 TXT records
pardot1082563=bb9161cabb68cab36a8aa71d47d62c09a067f8602a0280cfa207288e16dec45bgoogle-site-verification=_WltZVdB9HeIefSJ779rz3GQ4ydXHc8Uio8MHqFSmGssending_domain1082563=ad8f0fd9eaa3a92bff82df5d7760afc28b112820527ed912383b720ab0256568docusign=ae4244e0-0803-4629-bb36-94075b22cc652996133a0a4ab608476c07d4d3f9d39ca1b895cc39cee8285eatlassian-sending-domain-verification=100339a5-417a-45f3-848b-666c9ce75143apple-domain-verification=EjjRFJRsRVBN16AsfTNZZZoQubZ1fh3y8ugHMS=ms84865661ms-domain-verification=fe57195a-32f1-40bf-afb9-4f6d9d2a0753atlassian-domain-verification=4cLIKG1Wm7M3y3uT/pfGODrpKPjO5TgeX2fkIq5KNbs9ADMmagQF5g6fDE1Z3Gbd_e90y9hx5nwk8r84gy2zfjjgllz3eonefigma-domain-verification=b17984e169d20ec2a17613cb879a4017ec4d5e5b5b7308c5e927d985a5d71ce8-1760685943docusign=fcb7ceca-ba30-40b7-a171-d480524df537
Email authentication weak
- SPF
-
v=spf1 include:spf.protection.outlook.com include:aspmx.pardot.com include:spf_c.oraclecloud.com ip4:149.126.32.220 ip4:195.76.182.189 include:spf.mailjet.com -allstrict (-all) - DMARC
- not published
- DKIM
- no key found at common selectors
Certificate (current)
Sectigo Public Server Authentication CA OV R36
Expires in 50 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- findings
-
- CSP allows unsafe inline scripts/styles
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src https: data: 'unsafe-inline' 'unsafe-eval'; worker-src 'self' blob:- strict-transport-security
max-age=31536000; includeSubDomains; preload