servimedia.es
HTML metadata
Technology
- CMS
- Drupal
Third-party hosts loaded (2)
- cdn.iterwebcms.com×2
- cdn.jsdelivr.net×1
Social
DNS records live
- NS
-
- ns1.ascio.com
- ns2.ascio.com
- ns3.ascio.com
- ns4.ascio.com
- MX
-
- 10 servimedia-es.mail.protection.outlook.com
- TXT
-
Show 6 TXT records
google-site-verification=P78FYevXtQuTG2JVKlW2GzxSO3OqVirA7jgzmdSyOXgf/kYvafKOgJDlUega/mdOOtwxJjrb2nMLFvdCOWKBvoG1qMSCjAQeIzO1Qifkk2TStcoWBXbqS0hY9ixXvW3EQ==v=spf1 ip4:5.2.30.213 ip4:52.174.252.208 include:spf.mandrillapp.com include:servers.mcsv.net include:spf.protection.outlook.comry69r1w52cs7j9rc813sj7j9rjgqq026google-site-verification=mr0eh9xlHlJInAzwzUJjPZ24sFomG0HhcqOHkc4NMNsm ~all
Certificate (current)
Thawte TLS RSA CA G1
Expires in 13 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- weak content type protection
- missing Permissions Policy
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff, nosniff- content-security-policy
default-src 'self'; font-src 'self' fonts.gstatic.com; img-src data: 'self' *.mailchimp.com *.tiktokw.us mcusercontent.com *.flourish.studio *.once.es *.facebook.com *.twitter.com t.co tracker.metricool.com *.google-analytics.com *.google.es *.googletagmanager.com *.cloudfront.net stats.g.doubleclick.net mas.protecmedia.com connect.facebook.net; style-src 'self' 'unsafe-inline' *.mailchimp.com fonts.gstatic.com fonts.googleapis.com cdn.jsdelivr.net cdnjs.cloudflare.com unpkg.com *.cookiehub.eu; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.flourish.studio *.youtube.com *.ads-twitter.com tracker.metricool.com *.facebook.com *.google.com t.co mcusercontent.com *.facebook.net *.tiktok.com *.doubleclick.net *.list-manage.com cdn.iterwebcms.com *.twitter.com chimpstatic.com *.google.es *.googletagmanager.com *.google-analytics.com *.mailchimp.com *.gstatic.com mas.protecmedia.com *.googleapis.com *.google-analytics.com *.instagram.com public.tableau.com unpkg.com datawrapper.dwcdn.net c- strict-transport-security
max-age= 31536000; includeSubdomains;