vitaloleum.com
HTML metadata
Technology
- Server
- nginx
- CMS
- WordPress
- Fonts
-
- Google Fonts
Third-party hosts loaded (1)
- fonts.googleapis.com×1
Contact
- Phone
- Address
- st Desvern, Barcelona, EspañaFÓRMULA EMPRESARIAL YERA, S.L.Camino del Pilarejo, s/n23100
Registration
- Registrar
- Abion AB
- Created
- 2013-10-03
- Expires
- 2026-10-03 136 days left
- Updated
- 2025-09-26
- Name servers
-
- dns1.p05.nsone.net
- dns2.p05.nsone.net
- dns3.p05.nsone.net
- dns4.p05.nsone.net
- edns1.ultradns.biz
- edns1.ultradns.com
- edns1.ultradns.net
DNS records live
- NS
-
- dns1.p05.nsone.net
- dns2.p05.nsone.net
- dns3.p05.nsone.net
- dns4.p05.nsone.net
- edns1.ultradns.biz
- edns1.ultradns.com
- edns1.ultradns.net
- MX
-
- 10 mx07-0087dc01.pphosted.com
- 10 mx08-0087dc01.pphosted.com
- TXT
-
MS=ms91398595kxrr153k945258hs63jpf4dp9r6xgfn1q2jjwk51t5hnzyd7n2bbrwvghgdmyytr
Email authentication strong
- SPF
-
v=spf1 include:%{ir}.%{v}.%{d}.spf.has.pphosted.com -allstrict (-all) - DMARC
-
v=DMARC1; p=reject; rua=mailto:rua.dmarc@viterra.com; ruf=mailto:ruf.dmarc@viterra.compolicy: reject (enforced) - DKIM
- no key found at common selectors
Certificate (current)
RapidSSL TLS RSA CA G1
Expires in 132 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
Header values
- referrer-policy
no-referrer- x-frame-options
SAMEORIGIN- permissions-policy
accelerometer=(), autoplay=(), battery=(), camera=(), geolocation=(), gyroscope=(), interest-cohort=(), magnetometer=(), microphone=(), midi=(), payment=(), publickey-credentials-get=(), usb=()- x-content-type-options
nosniff- content-security-policy
default-src 'self' 'unsafe-inline' http: https:; script-src 'self' 'none' http: https:; style-src 'self' 'none' http: https:; img-src 'self' 'unsafe-inline' http: https:; connect-src 'self' http: https:; child-src 'self' 'none' http: https:; form-action 'self' http: https:; frame-ancestors 'self' 'none' http:; object-src 'self' 'unsafe-inline' http: https:; base-uri 'self' 'none' http: https:- strict-transport-security
max-age=31536000; includeSubDomains; preload