irundin.com
HTML metadata
Technology
- Server
- nginx
- PHP
- 8.2.31 security-only
- Cookie consent
-
- OneTrust
Third-party hosts loaded (1)
- cdn.cookielaw.org×2
Social
Contact
- Phone
- Address
- Pol. Arretxe Ugalde. Ezurriki kalea 12, 20305, Irun, Guipúzcoa, ES
Registration
- Registrar
- Name SRS AB
- Created
- 1999-02-03
- Expires
- 2027-02-03 242 days left
- Updated
- 2026-01-02
- Name servers
-
- ns10.nsprimario.com
- ns9.nsprimario.com
DNS records live
- NS
-
- ns10.nsprimario.com
- ns9.nsprimario.com
- MX
-
- 10 mx01.hornetsecurity.com
- 20 mx02.hornetsecurity.com
- 30 mx03.hornetsecurity.com
- 40 mx04.hornetsecurity.com
- TXT
-
MS=B62DC5CC115571CBCA775FF13EB8FE01096927C2
- Verified for
-
- Microsoft 365
Email authentication strong
- SPF
-
v=spf1 include:spf.ipzmarketing.com include:spf.protection.outlook.com include:spf.hornetsecurity.com include:_spf.elasticemail.com -allstrict (-all) - DMARC
-
v=DMARC1; p=quarantine; adkim=s; aspf=spolicy: quarantine - DKIM
-
- default:
v=DKIM1; p=DKIM1; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCspy+MkGZxo/oq4HPRh/uObrXtMOmRBl4mpEuUAGkmmbN3WRT1Gj8JG/mHrqxJo4B0HYHvh5Y2XXhc/z+a…
selectors probed - default:
Certificate (current)
R13
Expires in 62 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- weak frame protection
Header values
- referrer-policy
no-referrer- x-frame-options
ALLOW-FROM https://www.irundin.com/, ALLOW-FROM https://irundin.com/- permissions-policy
geolocation=(self), microphone=()- x-content-type-options
nosniff- content-security-policy
default-src 'self'; script-src 'unsafe-eval' 'unsafe-inline' 'self' https://*.cookielaw.org/ https://*.hs-analytics.net https://*.hs-banner.com https://*.hs-scripts.com https://*.hsadspixel.net https://*.hscollectedforms.net https://*.licdn.com https://*.google.com https://*.googletagmanager.com; style-src 'unsafe-inline' 'self'; object-src 'none'; base-uri 'self'; connect-src 'self' https://*.hubapi.com https://*.cookielaw.org https://*.hscollectedforms.net https://*.onetrust.com https://*.linkedin.com https://*.analytics.google.com https://*.google.com; font-src 'self' data:;frame-src 'self' https://*.googletagmanager.com https://sketchfab.com https://*.sketchfab.com; img-src 'unsafe-inline' 'self' https://*.cookielaw.org https://*.hsforms.com https://*.doubleclick.net https://*.linkedin.com https://*.hubspot.com https://*.google.com https://*.google.es; manifest-src 'self'; media-src 'self'; worker-src 'none';- strict-transport-security
max-age=31536000; includeSubDomains