jobandtalent.es
HTML metadata
Technology
- CDN
- Cloudflare
- Fonts
-
- Google Fonts
Third-party hosts loaded (11)
- images.ctfassets.net×42
- fonts.googleapis.com×3
- challenges.cloudflare.com×1
- fonts.gstatic.com×1
- www.jobandtalent.co×1
- www.jobandtalent.co.uk×1
- www.jobandtalent.com×1
- www.jobandtalent.com.pt×1
- www.jobandtalent.de×1
- www.jobandtalent.fr×1
- www.jobandtalent.se×1
Social
DNS records live
- NS
-
- ns-1018.awsdns-63.net
- ns-1052.awsdns-03.org
- ns-1772.awsdns-29.co.uk
- ns-257.awsdns-32.com
- TXT
-
google-site-verification=pAajkc7FiaGkS_SrcPKY9WqfDwIyKoDfKDodDxakXaIgoogle-site-verification=haxPIL7dlX9CdiUyv2qnZZzoAtllvMc5w-0cuu3q52U
Email authentication no MX
- SPF
- not published
- DMARC
- not published
- DKIM
- no key found at common selectors
Certificate (current)
WE1
Expires in 36 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- CSP uses wildcard sources
- missing Permissions Policy
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
base-uri 'self'; connect-src 'self' https://*.amplitude.com https://*.analytics.google.com https://*.google-analytics.com https://*.googletagmanager.com https://api.lever.co/ https://*.doubleclick.net https://*.g.doubleclick.net https://*.googlesyndication.com https://google.com https://googleadservices.com https://www.googleadservices.com https://livekit.platform.happyrobot.ai/ https://www.google.com https://www.jobandtalent.com/ wss://livekit.platform.happyrobot.ai www.googletagmanager.com https://cdn.amcharts.com https://*.ads.linkedin.com/ https://*.hotjar.com https://*.hotjar.io wss://*.hotjar.com https://videos.ctfassets.net/ https://assets.ctfassets.net/; default-src 'self' https://www.jobandtalent.com/; font-src 'self' https://fonts.gstatic.com/ https://*.hotjar.com; frame-ancestors https://app.contentful.com/ https://clara.works/ https://*.clara.works/ https://*.framer.app/; frame-src 'self' https://app.cal.com/ https://cal.com/ https://td.doubleclick.net https://www.googletag- strict-transport-security
max-age=31536000; includeSubDomains