volkswagen-comerciales.es
HTML metadata
Technology
- CMS
- Gatsby
Third-party hosts loaded (4)
- assets.volkswagen.com×10
- feature-services.vwonehub.io×1
- v3-113-1.gsl.feature-app.io×1
- vw-tam.lighthouselabs.eu×1
Social
DNS records live
- NS
-
- a1-210.akam.net
- a10-65.akam.net
- a11-64.akam.net
- a14-67.akam.net
- a28-64.akam.net
- a9-66.akam.net
- MX
-
- 10 mxa-006d7d02.gslb.pphosted.com
- 10 mxb-006d7d02.gslb.pphosted.com
- TXT
-
_duyurw863dpqvm3evssl7o6zard3amo
- Verified for
-
- Meta
Email authentication strong
- SPF
-
v=spf1 ip4:217.116.4.96/28 ip4:89.202.218.214 ip4:89.202.218.215 ip4:82.223.133.132 ip4:82.223.239.213 ip4:82.223.239.81 ip4:82.223.134.168 ip4:82.223.239.113 ip4:88.87.199.22 ip4:13.111.33.128 include:spf.protection.outlook.com include:cust-spf.exacttarget.com include:mail.zendesk.com include:mailgun.org include:spf-006d7d02.pphosted.com include:spf-006d7d03.pphosted.com -allstrict (-all) - DMARC
-
v=DMARC1;p=quarantine;pct=100;ri=86400;sp=none;rua=mailto:dmarc@volkswagengroup.es;ruf=mailto:dmarc@volkswagengroup.espolicy: quarantine · sp=none - DKIM
- no key found at common selectors
Certificate (current)
Amazon RSA 2048 M04
Expires in 87 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
DENY- x-content-type-options
nosniff- content-security-policy
default-src https: 'unsafe-eval' 'unsafe-inline'; script-src https: 'unsafe-eval' 'unsafe-inline'; style-src https: 'unsafe-eval' 'unsafe-inline'; img-src https: data: blob: *; media-src https: data: blob: *; object-src 'none'; frame-ancestors 'none'; connect-src * data: blob: ; base-uri 'self'; upgrade-insecure-requests; font-src https: 'unsafe-inline' data: 'unsafe-inline'; worker-src * blob:;- strict-transport-security
max-age=31536000