unicef.org.co
HTML metadata
Technology
- Server
- nginx
- CMS
- Drupal
- Analytics
-
- Google Tag Manager
Third-party hosts loaded (4)
- cdn.optimizely.com×1
- img.youtube.com×1
- www.googletagmanager.com×1
- www.gstatic.com×1
Contact
- Phone
- Address
- Calle 72 # 10-71 Piso 11Bogotá D.C, Colombia
DNS records live
- NS
-
- ns1.dongee.com
- ns2.dongee.com
- ns3.dongee.com
- MX
-
- 10 correo.unicef.org.co
- Verified for
-
- Meta
Email authentication partial
- SPF
-
v=spf1 ip4:91.99.132.180 ip4:129.41.174.38 ip4:62.4.14.73 ip4:163.172.126.21 include:spf.mandrillapp.com include:zcsend.net ip4:137.184.121.61 ?allneutral (?all) - DMARC
-
v=DMARC1; p=nonepolicy: none (monitoring only) - DKIM
-
- default:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA6OLRvTgpIEza5RT2lnpz4HzpOx8zoHtQVLS0LlH2Lq8CgzA7Mf2KN8PVWYFK9ShhZLgSOMdhKaAJjR… - k2:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAv2aC2KjGKLOwTweBY5A9RpjsxaBXR9r7OAU6U8/zn92ivImI75naUujWbItRI/QmL1jy5PWGqLwoUA…
selectors probed - default:
Certificate (current)
RapidSSL TLS RSA CA G1
Expires in 189 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- cross-origin-opener-policy
- cross-origin-resource-policy
- findings
-
- CSP allows unsafe inline scripts/styles
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN- permissions-policy
accelerometer=(), autoplay=(), browsing-topics=(), camera=(), clipboard-read=(), clipboard-write=(self), cross-origin-isolated=(), display-capture=(), encrypted-media=(), fullscreen=(self), gamepad=(), geolocation=(), gyroscope=(), hid=(), idle-detection=(), interest-cohort=(), keyboard-map=(), magnetometer=(), microphone=(), midi=(), payment=(), picture-in-picture=(), publickey-credentials-get=(self), screen-wake-lock=(), serial=(), sync-xhr=(self), usb=(), unload=(), web-share=(), xr-spatial-tracking=()- x-content-type-options
nosniff- content-security-policy
script-src 'self' 'report-sample' 'unsafe-eval' 'unsafe-inline' https://analytics.tiktok.com https://bat.bing.com/bat.js https://bat.bing.com/p/action/343191455.js https://cdn.firstoken.co/captures/js/2.1/sdk.js https://cdn.optimizely.com/js/5673342364024832.js https://connect.facebook.net https://googleads.g.doubleclick.net https://js-agent.newrelic.com https://script.hotjar.com https://scripts.clarity.ms https://snap.licdn.com/li.lms-analytics/insight.min.js https://static.addtoany.com https://static.hotjar.com https://maps.googleapis.com https://www.clarity.ms/tag/uet/343191455 https://www.clarity.ms/tag/vqk10ivps9 https://www.google.com/recaptcha/api.js https://www.googletagmanager.com https://cdn.siftscience.com/s.js https://my.rtmark.net https://s.pinimg.com https://wompijs.wompi.com/libs/js/v1.js https://checkout.wompi.co/widget.js https://www.googleadservices.com https://www.googletagservices.com https://cdnjs.cloudflare.com https://www.gstatic.com https://secure.mlstatic.com- strict-transport-security
max-age=63072000; includeSubDomains; preload- cross-origin-opener-policy
same-origin- cross-origin-resource-policy
same-origin