laboralkutxa.com

.com crawl

First seen 2026-04-11 · Last seen 2026-05-20 · ok HTTP/1.1 200 953 ms crawled 2026-05-18

DE · 2.21.239.24 · AS20940 Akamai International B.V.

Reputation 100/100

Classifying

HTML metadata

Title
Laboral Kutxa
Generator
Gatsby 4.25.4

Technology

CDN
Akamai
CMS
Gatsby
Analytics
  • Google Tag Manager

Third-party hosts loaded (2)

  • cdn.sanity.io×1
  • www.googletagmanager.com×1

Registration

Registrar
Tucows Domains Inc.
Created
2012-09-24
Expires
2026-09-24 126 days left
Updated
2026-02-17
Name servers
  • a1-159.akam.net
  • a11-65.akam.net
  • a24-65.akam.net
  • a4-67.akam.net
  • a7-66.akam.net
  • a8-64.akam.net

DNS records live

NS
  • a1-159.akam.net
  • a11-65.akam.net
  • a24-65.akam.net
  • a4-67.akam.net
  • a7-66.akam.net
  • a8-64.akam.net
MX
  • 0 mailcon.laboralkutxa.com
TXT
Show 10 TXT records
  • _6gxitd5ct47i0jrybgqi5xgrtrhfi4w
  • 3b05c78a-faa2-4db3-a4ea-dc4cf5dc4476
  • _n5k0an2qwhl1nvqeynd0v8337lqla1u
  • 59020058-cdde-4527-8c16-a486d5d19737
  • xx5gh0712bsqwdyhp6g7nhjnxrq5stl6
  • p0j7dvgmqb0cp59c9x9z2rxfp3rbsdh8
  • _e57kqz8vucoo5nz33r6h1mw1wvq3jk0
  • .citrix.mobile.ads.otp=0o3q2hgsegubre6t58vgik.
  • d9S3D/a6+L+XiEBoZw1YqMmPHxyKw0lrEb7g6Farc1Od5WqWoVkP1V7JG6ocsPFiOsf8Zx0CU0Wa4KQC5ZZXnQ==
  • _tfr3jsjvbk088t172l4cuh0nciloery
Verified for
  • Apple
  • Microsoft 365

Email authentication strong

SPF
v=spf1 mx ip4:195.55.185.12 ip4:195.55.185.166 ip4:195.55.185.165 include:spf.protection.outlook.com -all
strict (-all)
DMARC
v=DMARC1; p=quarantine; rua=mailto:informes_dmarc@laboralkutxa.com; ruf=mailto:informes_dmarc@laboralkutxa.com
policy: quarantine
DKIM
  • selector1: v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDJLi+evs3j66ESCWm7Zi9nPEN+p0a8COYZnYst6K0RtrrZCDJ065mHG0YWz2Ds38RX99hhHYWTk7c2ZzWHVq…
selectors probed

Certificate (current)

Thawte TLS ECC CA G1
from 2026-04-21 to 2026-11-06
Expires in 169 days

HTTP security headers

Header hygiene 70/100 Checked live page: https://www.laboralkutxa.com/

present
  • strict-transport-security
  • content-security-policy
  • x-content-type-options
findings
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
  • missing frame protection
  • missing Referrer Policy
  • missing Permissions Policy
Header values
x-content-type-options
nosniff
content-security-policy
default-src 'nonce-af579e5da75e799819c4958cbeafa560' 'self'; script-src 'nonce-af579e5da75e799819c4958cbeafa560' 'self' 'nonce-d8ddb30ce8c6b99de23a9c6bbeb367d5' 'strict-dynamic' 'unsafe-inline' www.googletagmanager.com consent.cookiebot.com recaptcha.google.com www.google.com www.gstatic.com cdn.sanity.io cdn.evgnet.com maps.googleapis.com www.livebeep.com www.laboralkutxachat.com careers.talentclue.com ddaas.dev.amelia.com dttdevqatest.ddaas.dev.amelia.com idsr.laboralkutxa.com bcdn-god.we-stats.com d3bzv4e6mx32qw.cloudfront.net d2xzr2b95x7lxb.cloudfront.net www.youtube.com *.laboralkutxa.com; style-src 'self' 'unsafe-inline' fonts.googleapis.com consent.cookiebot.com unpkg.com careers.talentclue.com d3bzv4e6mx32qw.cloudfront.net d2xzr2b95x7lxb.cloudfront.net db.onlinewebfonts.com; font-src 'self' fonts.googleapis.com fonts.gstatic.com db.onlinewebfonts.com data:; img-src 'self' data: blob: cdn.sanity.io *.sanity.io *.laboralkutxa.com www.gstatic.com www.googletagmanager.com www.googl
strict-transport-security
max-age=31536000 ; includeSubDomains

Linked from (16)