lolatoys.com
HTML metadata
Technology
- Server
- nginx
- CMS
- Gatsby
Third-party hosts loaded (1)
- cdn.jsdelivr.net×1
Social
Contact
- Phone
- Address
- Calle Marqués Viudo de Pontejos 1, 28012, Madrid, Madrid, ES
Registration
- Registrar
- 10dencehispahard, S.L.
- Created
- 2008-02-08
- Expires
- 2030-02-08 1361 days left
- Updated
- 2025-01-27
- Name servers
-
- ns-1359.awsdns-41.org
- ns-180.awsdns-22.com
- ns-1836.awsdns-37.co.uk
- ns-850.awsdns-42.net
DNS records live
- NS
-
- ns-1359.awsdns-41.org
- ns-180.awsdns-22.com
- ns-1836.awsdns-37.co.uk
- ns-850.awsdns-42.net
- MX
-
- 10 mail.lolatoys.com
- TXT
-
google-site-verification=LS8kIHyGfNhnCB0l-1JkwEfBTfmZ0po0AWXzfsmI8lM
Email authentication partial
- SPF
-
v=spf1 +a +mx +a:lolatoys.com -allstrict (-all) - DMARC
-
v=DMARC1; p=nonepolicy: none (monitoring only) - DKIM
-
- default:
v=DKIM1; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAthmx5Xw0pa2VMxbiIRo3Jza41JRfp4WlXXOmFAJkM9NOha1zy/Trey+UF7dLbKBbPAT4JDcvOkAF/oo3Ljp/C…
selectors probed - default:
Certificate (current)
R13
Expires in 51 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- content-security-policy-report-only
- x-frame-options
- x-content-type-options
- findings
-
- weak frame protection
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
SAMEORIGIN, SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
upgrade-insecure-requests;- strict-transport-security
max-age=31536000, max-age=15768000- content-security-policy-report-only
font-src *.cloudflare.com *.google.es *.twitter.com *.gstatic.com *.typekit.net *.twimg.com *.trustedshops.com *.googleapis.com www.paypalobjects.com fonts.gstatic.com use.typekit.net *.klarnacdn.net *.fontawesome.com data: 'self' 'unsafe-inline'; form-action *.twitter.com *.google.es https://sis.redsys.es/ https://sis.redsys.es geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src *.twitter.com *.google.es *.mozbar.moz.com *.youtube.com *.youtube-nocookie.com fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com