suramericana.com
HTML metadata
Technology
- Server
- SURA
- CMS
- WordPress
- Analytics
-
- Google Analytics
- Google Tag Manager
- Ads
-
- Meta Pixel
- Fonts
-
- Google Fonts
Third-party hosts loaded (10)
- www.google.com×2
- www.googletagmanager.com×2
- connect.facebook.net×1
- fonts.googleapis.com×1
- gmpg.org×1
- i.scdn.co×1
- open.scdn.co×1
- open.spotify.com×1
- www.google-analytics.com×1
- www.gruposura.com×1
Social
Contact
- Phone
Registration
- Registrar
- Hello Internet Corp
- Created
- 1998-02-25
- Expires
- 2027-02-24 279 days left
- Updated
- 2026-05-05
- Name servers
-
- dns1.p08.nsone.net
- dns2.p08.nsone.net
- dns3.p08.nsone.net
- dns4.p08.nsone.net
DNS records live
- NS
-
- dns1.p08.nsone.net
- dns2.p08.nsone.net
- dns3.p08.nsone.net
- dns4.p08.nsone.net
- MX
-
- 10 mail.suramericana.com.co
- 100 us2.mx1.mailhostbox.com
- 100 us2.mx2.mailhostbox.com
- 100 us2.mx3.mailhostbox.com
- Verified for
-
- GlobalSign
Email authentication weak
- SPF
-
v=spf1 mx:suramericana.com ip4:131.0.170.184 ip4:200.1.173.3 ip4:200.1.173.107 include:spf.protection.outlook.com redirect=_spf.mailhostbox.com include:mailgun.org -allstrict (-all) - DMARC
- not published
- DKIM
- no key found at common selectors
Certificate (current)
Sectigo Public Server Authentication CA OV R36
Expires in 293 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- findings
-
- short HSTS max-age
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src * self blob: data: gap:; style-src * self 'unsafe-inline' blob: data: gap:; script-src * 'self' 'unsafe-eval' 'unsafe-inline' blob: data: gap:; object-src * 'self' blob: data: gap:; img-src * self 'unsafe-inline' blob: data: gap:; connect-src self * 'unsafe-inline' blob: data: gap:; frame-src * self blob: data: gap:;, default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.google.com *.googletagmanager.com *.gstatic.com *.google-analytics.com connect.facebook.net *.spotifycdn.com *.youtube.com; style-src 'self' 'unsafe-inline' *.spotifycdn.com; font-src 'self' *.scdn.co data:; img-src 'self' data: *.spotifycdn.com *.google.com *.google.cl *.googletagmanager.com *.gruposura.com *.doubleclick.net *.facebook.com *.ytimg.com; connect-src 'self' analytics.google.com *.google-analytics.com *.google.com *.spotify.com *.facebook.com; frame-src 'self' *.google.com *.googletagmanager.com *.spotify.com *.facebook.com *.youtube.com indd.adobe.com; frame-ancestors 'self';- strict-transport-security
max-age=10886400