megablok.com
HTML metadata
Technology
- Analytics
-
- Google Tag Manager
Third-party hosts loaded (5)
- www.googletagmanager.com×3
- tag.oniad.com×1
- www.megablok.fr×1
- www.megablok.pt×1
- www.megablok.us×1
Contact
- Phone
Registration
- Registrar
- Soluciones Corporativas IP, SL
- Created
- 1999-03-31
- Expires
- 2027-03-31 316 days left
- Updated
- 2026-03-02
- Name servers
-
- ns1.dondominio.com
- ns2.dondominio.com
DNS records live
- NS
-
- ns1.dondominio.com
- ns2.dondominio.com
- MX
-
- 10 mx1.hc380-43.eu.iphmx.com
- 10 mx2.hc380-43.eu.iphmx.com
- TXT
-
google-site-verification=kWA71wEBAYXiKXIdZsZokexhm52jBW3Rq9YraHKRItoMS=ms59981956brevo-code:07a04d0b96031676927da64d7799d03b
Email authentication strong
- SPF
-
v=spf1 exists:%{i}.spf.hc380-43.eu.iphmx.com a ip4:20.50.182.59 ip4:82.223.190.24 include:sendgrid.net include:spf.protection.outlook.com -allstrict (-all) - DMARC
-
v=DMARC1; p=quarantine; rua=mailto:evillaverde@megablok.com; ruf=mailto:evillaverde@megablok.com; ri=84600; fo=1:d:spolicy: quarantine - DKIM
-
Show 4 DKIM selectors
- selector1:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDHjGwM6zKFqW+rxJhJY2spb5vv4Mi+VwkkkEmDMhmsjnWdPmRH/UkoiynuoEl9OefsOOBzbHnqDeMOiEUDAq… - mail:
k=rsa;p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDeMVIzrCa3T14JsNY0IRv5/2V1/v2itlviLQBwXsa7shBD6TrBkswsFUToPyMRWC9tbR/5ey0nRBH0ZVxp+lsmTxid2Y2z… - s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAsgeEdGFS+PjdLMh+UuxeHpJzt/NOH50KRjy/Lc3xQt0X+91yL4x6EaJ19N561j6GwgOv1T95Po6ge/wGZ/… - s2:
k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCvqnAOUh+PolC1KqaPkvyO2Kun6fpA4/xz22v129nxeZghg7Mw9BSe1UTGHAe42yd3ywTKafjHUP/o/iHQrQlWX3…
selectors probed - selector1:
Certificate (current)
Go Daddy Secure Certificate Authority - G2
Expires in 305 days
HTTP security headers
- present
-
- content-security-policy
- x-frame-options
- findings
-
- missing HSTS
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing content type protection
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
SAMEORIGIN- content-security-policy
default-src 'self'; style-src 'self' 'unsafe-inline' http://fonts.googleapis.com https://fonts.googleapis.com https://www.gravatar.com https://www.gstatic.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://cdn.cookie-script.com https://*.cloudfront.net https://www.googletagmanager.com https://www.google-analytics.com https://www.googleadservices.com https://static.criteo.net https://googleads.g.doubleclick.net https://sslwidget.criteo.com https://www.google.com https://code.jquery.com https://cdnjs.cloudflare.com https://www.gstatic.com https://maps.googleapis.com https://tpc.googlesyndication.com https://tag.oniad.com https://diffuser-cdn.app-us1.com https://static.hotjar.com https://track.adform.net https://script.hotjar.com https://prism.app-us1.com https://trackcmp.net; font-src 'self' https://fonts.gstatic.com data: ; img-src * data: blob: https://www.google-analytics.com https://www.google.com https://www.googletagmanager.com https://www.google.es https://www.gravatar.c