viajeselcorteingles.com.co
HTML metadata
Technology
- CDN
- Akamai
- Analytics
-
- Google Tag Manager
Third-party hosts loaded (6)
- s3.amazonaws.com×2
- sc.cdnpt.com×2
- widgets.priceres.co×2
- b2b-b2b2c.s3.amazonaws.com×1
- cdn.onesignal.com×1
- www.googletagmanager.com×1
Contact
DNS records live
- NS
-
- dns3.elcorteingles.es
- dns4.elcorteingles.es
- dns5.elcorteingles.es
- dns6.elcorteingles.es
- MX
-
- 10 viajeselcorteingles-com-co.mail.protection.outlook.com
- TXT
-
zscaler-verification-44864592-16042026-K3wNnYLpSyjjyvtvzltzg64brgy1v8k58xczn4s9ygrovag_verification_token=3B94B8DEC29C4B9A83C5C58082177389
- Verified for
-
- Meta
- Microsoft 365
Email authentication strong
- SPF
-
v=spf1 exists:%{i}.spf.hc1050-60.c3s2.iphmx.com include:spf.protection.outlook.com ip4:185.90.80.128/25 -allstrict (-all) - DMARC
-
v=DMARC1; p=reject; fo=1; ri=3600; rua=mailto:bf6aa36e@inbox.eu.redsift.cloud; ruf=mailto:bf6aa36e@inbox.eu.redsift.cloudpolicy: reject (enforced) - DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAq5tjWKzkr18vTA98newsawWrdEBdJMIIXkmIDz0f+YRy4YaEa+bwWKbF+QgOkA3ukwt4Vf4dSMBsh7… - selector2:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA3jZhUKnrjKhTpwfxosT45Io8CQgMo2GrFGLCv0egqvmbdEWNDbT7SiDctm8jbALIMcHZtqDiSOoyQE…
selectors probed - selector1:
Certificate (current)
DigiCert Global G2 TLS RSA SHA256 2020 CA1
Expires in 90 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN- permissions-policy
camera=(), geolocation=(), gyroscope=(), microphone=(), usb=(), web-share=()- x-content-type-options
nosniff- content-security-policy
frame-ancestors 'self'; script-src 'self' cdnpt.com *.cdnpt.com *.priceres.com.mx *.priceres.com *.priceres.co *.googleapis.com *.googletagmanager.com *.onesignal.com onesignal.com *.google-analytics.com *.hotjar.com *.ladesk.com 'unsafe-inline' 'unsafe-eval' connect.facebook.net api.beyond-experience.com www.thehotelsnetwork.com js.hs-scripts.com services.xg4ken.com static.sojern.com snap.licdn.com svht.tradedoubler.com cdn.mouseflow.com tracker.metricool.com assets.anytrack.io cdnjs.cloudflare.com cdn.jsdelivr.net cdn.sift.com *.bing.com *.us.mouseflow.com *.googleadservices.com *.doubleclick.net *.securitytrfx.com *.metaads.io *.tradedoubler.com *.clarity.ms *.bing.com tally.so;; object-src 'none';- strict-transport-security
max-age=31536000 ; includeSubDomains