openfinance.es
HTML metadata
Technology
- Server
- openfinance
- CMS
- WordPress
- Analytics
-
- Google Tag Manager
- Fonts
-
- Google Fonts
Third-party hosts loaded (4)
- fonts.googleapis.com×2
- www.google.com×2
- gmpg.org×1
- www.googletagmanager.com×1
Social
Contact
DNS records live
- NS
-
- dns100.ovh.net
- ns100.ovh.net
- MX
-
- 10 openfinance-es.mail.protection.outlook.com
- TXT
-
Show 7 TXT records
anthropic-domain-verification-d3ymkq=Bj1BHzhSoC9XGITFJGo7K1dQYgoogle-site-verification=ZFiXcMsRUwGUTw1UP5fELFMH6UYV6aBYuTR4kB0AEmIatlassian-domain-verification=2vO1qC1TCRNeuoJtyIwJaZMByyTUMyJa2evYQRkAVEsUfHuoms2xoCDc6Yv5KBJ1sophos-domain-verification=83b8f80b6c14ac9ee3a306baffe3e632ed9b3de7912caa0e4952db1697c6c65aapple-domain-verification=Z4PVGvzCcTaT7w9Aatlassian-sending-domain-verification=b03f6551-ae15-42cd-be2a-a666e4b6d1b81|www.openfinance.es
Email authentication strong
- SPF
-
v=spf1 ip4:5.39.51.211 ip4:193.70.18.130 ip4:5.39.51.212 include:mx.ovh.com include:spf.protection.outlook.com include:spf.emailsignatures365.com include:amazonses.com ~allsoftfail (~all) - DMARC
-
v=DMARC1;p=reject;pct=100;rua=mailto:reportphishing@openfinance.es;sp=reject;aspf=s;policy: reject (enforced) · sp=reject - DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDKk99NJqtiOXztadlQfXiowCq6ElsK1XbERetfuG56nYVvdyyTpSccrhbs7FpCbsvmu4eMBPbMaoS2yddO+g…
selectors probed - selector1:
Certificate (current)
Sectigo Public Server Authentication CA OV R36
Expires in 186 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Permissions Policy
Header values
- referrer-policy
no-referrer-when-downgrade- x-frame-options
DENY- x-content-type-options
nosniff- content-security-policy
frame-ancestors 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://*.list-manage.com/ https://www.googletagmanager.com/ https://www.google.com/recaptcha/ https://www.gstatic.com/; worker-src 'self' blob:;img-src 'self' data: https://openfinance.es https://www.google.com https://www.gstatic.com https://px.ads.linkedin.com;- strict-transport-security
max-age=63072000; includeSubDomains