itvtalleres.com
HTML metadata
Technology
- Server
- Microsoft-IIS
- Fonts
-
- Google Fonts
Third-party hosts loaded (5)
- cdnjs.cloudflare.com×2
- stackpath.bootstrapcdn.com×2
- www.gstatic.com×2
- cdn.jsdelivr.net×1
- fonts.googleapis.com×1
Registration
- Registrar
- Nominalia Internet SL
- Created
- 2024-07-18
- Expires
- 2028-07-18 789 days left
- Updated
- 2025-07-07
- Name servers
-
- dns1.nominalia.com
- dns2.nominalia.com
DNS records live
- NS
-
- dns1.nominalia.com
- dns2.nominalia.com
- MX
-
- 10 mail.nominalia.com
- TXT
-
v=spf1 include:spf.webapps.net ~all
Certificate (current)
Thawte TLS RSA CA G1
Expires in 65 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- weak frame protection
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
SAMEORIGIN, SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src 'self' 'unsafe-inline' 'unsafe-eval' cdnjs.cloudflare.com stackpath.bootstrapcdn.com d3js.org code.jquery.com *.googleapis.com analytics.tiktok.com cdn.linkedin.oribi.io *.analytics.google.com cdnjs.cloudflare.com ajax.aspnetcdn.com *.aspnetcdn.com www.google.com www.gstatic.com cdn.jsdelivr.net tile.openstreetmap.org www.googletagmanager.com www.google-analytics.com ssl.google-analytics.com www.googleadservices.com connect.facebook.net stats.g.doubleclick.net googleads.g.doubleclick.net static.hotjar.com script.hotjar.com cdn.botframework.com chatbotapitoken.azurewebsites.net snap.licdn.com analytics.google.com directline.botframework.com wss://directline.botframework.com https://static.ads-twitter.com/uwt.js https://equipoitv.applusiteuve.com https://use.typekit.net https://p.typekit.net http://produccion-applusiteuve-website.xtranet.es; img-src 'self' blob: data: https://t.co/i/adsct https://analytics.twitter.com/ https://px.ads.linkedin.com/ https://cdnjs.cloudflare.com- strict-transport-security
max-age=31536000; includeSubDomains, max-age=31536000; includeSubDomains; preload