totto.com
HTML metadata
Technology
- Server
- Microsoft-IIS
- Analytics
-
- Google Tag Manager
Third-party hosts loaded (2)
- maxcdn.bootstrapcdn.com×1
- www.googletagmanager.com×1
Registration
- Registrar
- Domain.com - Network Solutions, LLC
- Created
- 2001-04-04
- Expires
- 2027-04-04 318 days left
- Updated
- 2026-03-15
- Name servers
-
- pdns13.domaincontrol.com
- pdns14.domaincontrol.com
DNS records live
- NS
-
- pdns13.domaincontrol.com
- pdns14.domaincontrol.com
- MX
-
- 0 totto-com.mail.protection.outlook.com
- TXT
-
Show 8 TXT records
fe8b0v2aodhd2np4fovogt46538eejdnlt3jq2133vngu230ss1uUo8jh0bmb8ia5j831gsv3ri88lsophos-domain-verification=da5c019e1ef0c45f5f22266c8c25ac25a32ff1ab8bed3c1d2759193fe3787be4FIZWAN4HGWOITAATGFJFFNG7QCQ6XU1AT2ANLT4Guo8mpqt2iec6mavjuuhf629feg7dhsfta9nt945v4kvensd63pneh0vata2uv689kghben4k2h5oq4
- Verified for
-
- Meta
- Microsoft 365
Email authentication strong
- SPF
-
v=spf1 ip4:190.216.154.214 ip4:190.60.75.244 include:spf.protection.outlook.com include:spf.mandrillapp.com include:mailgun.org ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=reject; rua=mailto:yimy.sanchezb@totto.com,mailto:jorge.ramos@totto.com;policy: reject (enforced) - DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCWf5hdvbd05VQWYL12yFT8rLF28EbaCKLx7Jr9yrEWZzF44k+Y8UX7a62gYMeG+MjhhlWw4Fko62F0FYJbEe… - selector2:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA0p9aDSSvOO1itpNh0tX4ghQHZVHRK6MZH4EunA5Q8Xf1cZM+Sr3+3X867cuMMkEllUTXgsmf3y8WH2…
selectors probed - selector1:
Certificate (current)
Go Daddy Secure Certificate Authority - G2
Expires in 74 days
HTTP security headers
- present
-
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- missing HSTS
- CSP allows unsafe inline scripts/styles
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN- permissions-policy
geolocation=(), microphone=(), camera=()- x-content-type-options
nosniff- content-security-policy
default-src 'self'; script-src 'self' 'unsafe-inline'; style-src 'self' 'unsafe-inline'; img-src 'self' data: https:; font-src 'self' https: