tombola.es
HTML metadata
Technology
- CDN
- Cloudflare
- Analytics
-
- Google Tag Manager
- Cookie consent
-
- OneTrust
- Fonts
-
- Google Fonts
Third-party hosts loaded (6)
- fonts.googleapis.com×2
- cdn-ukwest.onetrust.com×1
- cdn.optimizely.com×1
- fonts.gstatic.com×1
- uk-aws-cloud-resources-2.tombola.com×1
- www.googletagmanager.com×1
Social
Contact
- Phone
DNS records live
- NS
-
- donna.ns.cloudflare.com
- logan.ns.cloudflare.com
- MX
-
- 0 tombola-es.mail.protection.outlook.com
- Verified for
-
- Atlassian
- Meta
- Microsoft 365
Email authentication partial
- SPF
-
v=spf1 include:amazonses.com include:spf.protection.outlook.com ip4:178.23.131.142 ip4:178.23.128.178 ip4:178.23.128.179 ip4:178.23.131.230 -allstrict (-all) - DMARC
-
v=DMARC1; p=none; sp=none; rua=mailto:darren.lawson@tombola.com; ruf=mailto:darren.lawson@tombola.com; rf=afrf; pct=100; ri=86400policy: none (monitoring only) · sp=none - DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDMjb9k5raCJwErIxoLJRXR71Gl4nBmxSUYMCgcG+KhHnX6sSJJHKVVLrZaTBfZZNCP7VOI8C0rg+0AOlF4Rf…
selectors probed - selector1:
Certificate (current)
WE1
Expires in 85 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- findings
-
- short HSTS max-age
- CSP uses wildcard sources
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
frame-ancestors 'self' *.tombola.com *.tombola.es https://app.optimizely.com https://localhost:7288/;- strict-transport-security
max-age=2592000