invias.gov.co

.co crawl

First seen 2026-04-11 · Last seen 2026-05-20 · ok HTTP/1.1 200 6739 ms crawled 2026-05-19

US · 45.60.31.26 · AS19551 Incapsula Inc

Reputation 92/100 no dmarc policy

Classifying

HTML metadata

Title
Portal Invías - Colombia
Description
Instituto Nacional de Vías INVÍAS - Colombia
Language
es
Canonical
https://www.invias.gov.co

Open Graph

url
https://www.invias.gov.co
title
Portal Invías - Colombia
locale
es_la
site name
SedeElectronica Invias
description
Instituto Nacional de Vías INVÍAS - Colombia
locale:alternate
es_es

Technology

Analytics
  • Google Tag Manager

Third-party hosts loaded (4)

  • img.youtube.com×10
  • www.googletagmanager.com×2
  • translate.google.com×1
  • www.google.com×1

Social

Contact

Email
Phone

DNS records live

NS
  • name1.mediacommerce.com.co
  • name2.mediacommerce.com.co
  • name4.mediacommerce.com.co
MX
  • 0 invias-gov-co.mail.protection.outlook.com
TXT
  • js9v19iod4rm7i89eebpr30045
  • sophos-domain-verification=0854307496b591dac43045b5a3aa87b09ac59bd6
  • UZzWzlGRl9MNXlLULGMJfxmxhv8XVtXa9H81R+PggSq0b9y2eGpiNOOr1sg7B44lWT3mQYyLyv45piqhJdUuhw==
Verified for
  • Apple
  • GlobalSign
  • Google
  • Microsoft 365

Email authentication weak

SPF
v=spf1 ip4:190.121.155.88 include:spf.protection.outlook.com -all
strict (-all)
DMARC
not published
DKIM
no key found at common selectors

Certificate (current)

Go Daddy Secure Certificate Authority - G2
from 2025-09-30 to 2026-09-30
Expires in 133 days

HTTP security headers

Header hygiene 90/100 Checked live page: https://www.invias.gov.co/

present
  • strict-transport-security
  • content-security-policy
  • x-frame-options
  • x-content-type-options
  • referrer-policy
  • permissions-policy
findings
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
Header values
referrer-policy
strict-origin
x-frame-options
SAMEORIGIN
permissions-policy
geolocation=(), midi=(), sync-xhr=(self 'https://*.nexura.com/*' 'https://aerocivil.gov.co/*'), microphone=(), camera=(), magnetometer=(), gyroscope=(), fullscreen=(self 'https://*.nexura.com/*' 'https://aerocivil.gov.co/*'), payment=()
x-content-type-options
nosniff
content-security-policy
script-src 'self' blob: 'unsafe-inline' 'unsafe-eval' https://aerocivil.gov.co https://liveconnect.chat/ https://aura.abrahamchatbot.com/ https://tracker.metricool.com/ https://cdn.jsdelivr.net/ https://cdn.userway.org/widgetapp/2024-10-25-08-38-44/widget_app_base_1729845524407.js https://cdn.userway.org/widget.js https://cdnjs.cloudflare.com https://sdk.mercadopago.com/js/v2 https://checkout.wompi.co/widget.js wolkvox-cobrowsing-agent-fd5zvw7swa-ue.a.run.app https://wolkvox-cobrowsing-agent-fd5zvw7swa-ue.a.run.app widget02.wolkvox.com d335luupugsy2.cloudfront.net wolkvox-cobrowsing-agent-fd5zvw7swa-ue.a.run.app https://platform.bluemessaging.net *.tableau.com *.google.com *.google-analytics.com *.gstatic.com *.googleapis.com https://assets.zendesk.com https://connect.facebook.net *.hotjar.com *.twitter.com *.twimg.com *.googletagmanager.com; img-src 'self' blob: https://files.liveconnect.chat/ https://liveconnect.chat/ https://aura.abrahamchatbot.com/ https://tracker.metricool.com/
strict-transport-security
max-age=31536000; includeSubDomains

Links to (33)

Linked from (8)