hmhospitales.com
HTML metadata
Technology
- CDN
- Cloudflare
- Analytics
-
- Cloudflare Insights
- Cookie consent
-
- Cookiebot
Third-party hosts loaded (2)
- consent.cookiebot.com×1
- static.cloudflareinsights.com×1
Social
Contact
Registration
- Registrar
- Dinahosting s.l.
- Created
- 2011-01-19
- Expires
- 2027-01-19 244 days left
- Updated
- 2025-12-22
- Name servers
-
- ada.ns.cloudflare.com
- rex.ns.cloudflare.com
DNS records live
- NS
-
- ada.ns.cloudflare.com
- rex.ns.cloudflare.com
- MX
-
- 10 mxa-004e2c01.gslb.pphosted.com
- 10 mxb-004e2c01.gslb.pphosted.com
- TXT
-
Show 11 TXT records
have-i-been-pwned-verification=d6c3b80c1fe23d45354016fdbec9a38bmsfpkey=63lrrge8sro2yp5siel9vsrkcone-time-verification=8a04b866-add7-430e-bbe0-1bbc044a712eDynatrace-site-verification=e020620c-e35b-40ba-bb3a-185e77d5ce5d__8g9k72v5hiast063qcajb5nj5tMS=ms56869484MS=ms62375315MS=ms84544719d365mktkey=1egqixy6ipehr4rahlu039txnd365mktkey=34x1gnoxmifv57x3ew4uz2hrlgoogle-gws-recovery-domain-verification=60556628google-site-verification=CUEuHsbn0_u4_8R-1If1fRNaGCIn7IdSO0N-kjybSwE
Email authentication partial
- SPF
-
v=spf1 include:spf.protection.outlook.com ip4:185.132.183.52 ip4:212.4.96.83 ip4:185.183.30.110 ip4:91.215.64.147 ip4:212.4.98.26 ip4:212.4.111.188 ip4:54.240.49.120 ip4:54.240.49.121 ip4:212.4.107.191 ip4:212.4.107.20 ip4:212.4.108.179 ip4:212.4.122.120 ip4:212.4.98.26 a:listahm.hmhospitales.com a:listaformacion.hmhospitales.com include:servers.mcsv.net a:servweb01.gnet.es include:_spf.stampymail.com -allstrict (-all) - DMARC
-
v=DMARC1; p=none; pct=100; rua=mailto:b8699467e2c34f419bca0ae85e2d167c@dmarc-reports.cloudflare.net,mailto:admin@hmhospitales.com;policy: none (monitoring only) - DKIM
-
Show 6 DKIM selectors
- selector1:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQC6H+Wvas+U8bHoy4UTUjvjoTmp/KMCRHRKzj28mhqC6ET7OPoj4CGb4V94qdeBzma3MpRfYXOMUO8Bp4Zp58… - selector2:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEArZgoeoWZpUaKwUcWmBxSrkZZPpS4C0DXJfBQWpu8cjudeQ3/U8UIFlVVOizvI1oAHljX8LWBXB1il/… - k1:
k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDbNrX2cY/GUKIFx2G/1I00ftdAj713WP9AQ1xir85i89sA2guU0ta4UX1Xzm06XIU6iBP41VwmPwBGRNofhBVR+e6WHUo… - mail:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDmMd2Tj9Y2GhxAvm98t2rps7iCv8SUoHjXq7FXNI7F91EaWYUDfwYsXNGc/5NvYhu4da3KaGqr9M4UjNfkZM… - s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA2nSFym0PzrVaIdShRsz5EIdHsvonXSiW3c+16uu4+9ToaAg0nWb5wSbE44/yoCFIgvHk93rZWURf8JX61d… - s2:
k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDT1y94XM69BEhpAcSWi+RTJEDpbXVUmW3Kva+Rhyjahx9bU3yPOx0Qz8IHBJACZtXCqJ+VfegCv4Cw7mg+0CemaH…
selectors probed - selector1:
Certificate (current)
Sectigo Public Server Authentication CA DV R36
Expires in 184 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
base-uri 'none'; default-src 'self'; frame-ancestors 'self'; object-src 'none'; upgrade-insecure-requests; form-action 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' challenges.cloudflare.com *.google-analytics.com region1.google-analytics.com *.googletagmanager.com *.googleapis.com *.google.com *.gstatic.com *.azureedge.net unpkg.com *.cookiebot.com *.cloudflare.com cloudflareinsights.com *.cloudflareinsights.com *.amazonaws.com *.cloudfront.net hmhospitales.com *.hmhospitales.com *.talentclue.com *.youtube.com *.youtube-nocookie.com script.hotjar.com static.hotjar.com t.contentsquare.net app.contentsquare.com *.contentsquare.net www.googleadservices.com *.googleleadservices.com *.g.doubleclick.net *.googlesyndication.com connect.facebook.net facebook.com www.facebook.com *.facebook.net cdn.jsdelivr.net tags.srv.stackadapt.com app.konverting.io *.sealmetrics.com; script-src-elem 'self' 'unsafe-inline' 'unsafe-eval' challenges.cloudflare.com *.google-analytics.com region1.goog- strict-transport-security
max-age=31536000; includeSubDomains