ventanas.es
HTML metadata
Technology
- CDN
- Cloudflare
Third-party hosts loaded (8)
- fastly.jsdelivr.net×2
- c.delivery.consentmanager.net×1
- cdn.consentmanager.net×1
- static.zdassets.com×1
- www.fensterversand.at×1
- www.fensterversand.ch×1
- www.fensterversand.com×1
- www.finestre.com×1
Social
Contact
- Phone
DNS records live
- NS
-
- annabel.ns.cloudflare.com
- igor.ns.cloudflare.com
- MX
-
- 0 ventanas-es.mail.protection.outlook.com
- Verified for
-
- Microsoft 365
Email authentication strong
- SPF
-
v=spf1 include:spf.mailjet.com include:spf.komfortkasse.eu include:spf.protection.outlook.com include:mail.zendesk.com -allstrict (-all) - DMARC
-
v=DMARC1; p=reject; rua=mailto:68800118@mxtoolbox.dmarc-report.com,mailto:dfaba30dcd77485b8d74287b51483f6b@dmarc-reports.cloudflare.net; ruf=mailto:68800118@forensics.dmarc-report.com; pct=90policy: reject (enforced) · pct=90 - DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAyRPJF47kJUJAmClyavnP0OgMp3n7l2i/v/MsJCOLoq1dZYkM+7RxrQFl/nBGVPoc+AgmyfePoOnoug… - k2:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAv2aC2KjGKLOwTweBY5A9RpjsxaBXR9r7OAU6U8/zn92ivImI75naUujWbItRI/QmL1jy5PWGqLwoUA…
selectors probed - selector1:
Certificate (current)
WE1
Expires in 87 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing frame protection
- missing content type protection
- missing Referrer Policy
- missing Permissions Policy
Header values
- content-security-policy
default-src 'self' 'unsafe-inline' 'unsafe-eval' blob: data: *.fenster.com *.fensterversand.com *.fensterversand.at *.fensterversand.ch *.fenetre24.com *.fenetre24.be *.finestre.com *.ventanas.es *.windows24.com *.haustueren.de *.neuffer.de *.neuffer-payment.com *.k8s.nng-stage.de *.nng-prod.de *.amazonaws.com *.cloudfront.net *.cloudflare.com *.google.com *.google.ad *.google.ae *.google.com.af *.google.com.ag *.google.al *.google.am *.google.co.ao *.google.com.ar *.google.as *.google.at *.google.com.au *.google.az *.google.ba *.google.com.bd *.google.be *.google.bf *.google.bg *.google.com.bh *.google.bi *.google.bj *.google.com.bn *.google.com.bo *.google.com.br *.google.bs *.google.bt *.google.co.bw *.google.by *.google.com.bz *.google.ca *.google.cd *.google.cf *.google.cg *.google.ch *.google.ci *.google.co.ck *.google.cl *.google.cm *.google.cn *.google.com.co *.google.co.cr *.google.com.cu *.google.cv *.google.com.cy *.google.cz *.google.de *.google.dj *.google.dk *.g- strict-transport-security
max-age=31536000