mercanza.es
HTML metadata
Technology
- Server
- Apache
- CMS
- WordPress
Third-party hosts loaded (1)
- gmpg.org×1
Social
DNS records live
- NS
-
- ns1-a.entorno.com
- ns1-b.entorno.es
- ns2-c.entorno.cat
- ns2-d.entorno.info
- MX
-
- 0 mercanza-es.mail.protection.outlook.com
- TXT
-
Show 9 TXT records
logmein-verification-code=0d17a090-e8eb-42d7-b721-f45e0c0ff9a8google-site-verification=s5Y6-i_CCdaYtnkRreLpBWrpzIFTZns7vXcXmQmrpQwMS=ms46874881MS=ms53956208qxfssr9q3k95rrptpbzvgxf9z0vs5qydynr9vhr1xtkh9cthcypf16tqws9hhck2MS=11086BCC6E6DAAE288070A8F3A1842A64B6ADFDDcLBpy769XUsiwMShFozYfg+IfF4AxoZfpHPgieO0qsE=facebook-domain-verification=w5tz6q36qfxwueeosntkd3ehev54iv
Email authentication partial
- SPF
-
v=spf1 ip4:88.87.139.9 ip4:88.87.136.10 a:mail.mercanza.es a:correo.mercanza.es include:spf.ipzmarketing.com include:spf.protection.outlook.com ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=none; rua=mailto:net@mercanza.es; ruf=mailto:net@mercanza.es,mailto:6e40efad@forensics.dmarc-report.com; sp=none; fo=1; aspf=rpolicy: none (monitoring only) · sp=none - DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDCsgvZQGTCjqhD6m4cHQtFZLQbi+/x8M9mOU14k+vg5ohhnpamBb6JFRWSJzvZT8mzoWBi8ISCmp6hOrOVn9… - selector2:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDW4Nf7CbstHOVg/R3fGhkMUQv2D8ur4ArJ5MCg3VNsaSADnut7ZM3Iw8OravVxvhI5Km6Qz8DLMwR2Llq/06…
selectors probed - selector1:
Certificate (current)
Sectigo Public Server Authentication CA OV R36
Expires in 176 days
HTTP security headers
- present
-
- content-security-policy
- findings
-
- missing HSTS
- CSP allows unsafe inline scripts/styles
- missing frame protection
- missing content type protection
- missing Referrer Policy
- missing Permissions Policy
Header values
- content-security-policy
base-uri 'self'; frame-ancestors 'none'; connect-src 'self' https://region1.analytics.google.com https://www.google.es; default-src 'self'; font-src 'self' data:; frame-src 'self' youtube.com www.youtube.com; img-src 'self' data: https://www.google.es https://i.ytimg.com; manifest-src 'self'; media-src 'self'; object-src 'none'; script-src 'unsafe-inline' 'unsafe-eval' 'self' https://www.googletagmanager.com/gtag/js; style-src 'unsafe-inline' 'self'; worker-src 'none';
Links to (6)
- aeiq.org×2
- linkedin.com×2
- lyviagroup.com×2
- qlikacademy.com×2
- x.com×2
- youtube.com×2