jazztel.com
HTML metadata
Technology
- Server
- istio-envoy
- CMS
- Next.js
- Fonts
-
- Google Fonts
Third-party hosts loaded (4)
- eshop.prod.k8s.masmovil.com×8
- cdn.engagement.coremedia.cloud×1
- fonts.googleapis.com×1
- fonts.gstatic.com×1
Social
Contact
- Address
- Paseo del Club Deportivo 1, Parque Empresarial La Finca, Edificio 8, Pozuelo de Alarcón (Madrid), 28223, Madrid, Madrid, España
Registration
- Registrar
- Nominalia Internet SL
- Created
- 1997-07-15
- Expires
- 2026-07-14 55 days left
- Updated
- 2022-02-03
- Name servers
-
- dns.jazztel.es
- dns2.jazztel.es
DNS records live
- NS
-
- dns.jazztel.es
- dns2.jazztel.es
- MX
-
- 4 masmovil.in.tmes.trendmicro.eu
- TXT
-
Show 9 TXT records
_validation-contactemail = certificados.ciberseguridad@masorange.esamazonses:MfK4o+DyJPdUeLsoSzgtwW6Qn3IEHIJGQuUqSITJfCk=v3w34gxg9nfl8k7bfr5sh7cvrfn94mdjgoogle-site-verification=ciHpZKa6XXj9aND5LEKGGWKwvBFlKtgP2pjMnXTh45sn828zw6wmvb43qv910lrsk5v6wpht1mx8fr1d3mn5e10s6jl5c28oto8gstmes=a5d2697cc4215d47bd7355155845e162dtm-domain-verification=kNGrfBkd9JIHzk6FlJVuqENRHrm42Zim_kbYcuy7UAsMS=ms29847927
Email authentication partial
- SPF
-
v=spf1 mx ip4:85.62.13.215 ip4:83.231.36.67 include:spf.tmes.trendmicro.eu include:_spf.retarus.com include:_spf.general.transactional-mail-a.com include:spf.protection.outlook.com include:_spf.qualtrics.com -allstrict (-all) - DMARC
-
v=DMARC1; p=none; rua=mailto:att.cliente.jazztel@jazztel.compolicy: none (monitoring only) - DKIM
- no key found at common selectors
Certificate (current)
WR3
Expires in 86 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Referrer Policy
Header values
- x-frame-options
SAMEORIGIN- permissions-policy
geolocation=(self "https://www.jazztel.com"), microphone=(),- x-content-type-options
nosniff- content-security-policy
base-uri 'self'; block-all-mixed-content; upgrade-insecure-requests; child-src blob:; default-src 'self'; script-src 'self' 'unsafe-eval' 'unsafe-inline' blob: *.indra-netplus.com *.ads-twitter.com *.adswizz.com *.amazonaws.com *.amazon-adsystem.com *.analytics.google.com *.aptica.es *.bankofafrica.ma *.bing.com *.bing.net *.bucket.co *.byside.com *.capitalone.com *.clarity.ms cdnjs.cloudflare.com/ajax/libs/three.js/* *.configcat.com *.contentful.com *.cookielaw.com *.cookielaw.org *.ctfassets.net *.conversionsapigateway.com *.doubleclick.net *.engagement.coremedia.cloud *.eu2.segmentapis.com *.facebook.com *.facebook.net *.go2sdk.com *.google-analytics.com *.google.com *.google.es *.googleadservices.com *.googleapis.com *.googlesyndication.com *.googletagmanager.com *.gstatic.com *.jazztel.com *.jsdelivr.net *.krxd.net *.masstack.com *.masmovil.com *.masmovil.es mpc2-prod-1-is5qnl632q-uc.a.run.app *.onetrust.com *.optimizely.com *.orange.es *.orsac.net *.paa-reporting-advertising.amaz- strict-transport-security
max-age=15552000; includeSubDomains