wonnowawards.com
HTML metadata
Technology
- Server
- Apache
- Stack
- Laravel
Social
Registration
- Registrar
- EuroDNS S.A.
- Created
- 2018-02-06
- Expires
- 2027-02-06 261 days left
- Updated
- 2024-01-15
- Name servers
-
- ns1.lacaixa.com
- ns2.lacaixa.com
DNS records live
- NS
-
- ns1.lacaixa.com
- ns2.lacaixa.com
- MX
-
- 1 aspmx.l.google.com
- 10 alt3.aspmx.l.google.com
- 10 alt4.aspmx.l.google.com
- 5 alt1.aspmx.l.google.com
- 5 alt2.aspmx.l.google.com
- Verified for
-
Email authentication strong
- SPF
-
v=spf1 include:_spf.google.com -allstrict (-all) - DMARC
-
v=DMARC1;p=reject;fo=1;rua=mailto:caixa-bank@rua.agari.com,mailto:dmarc_rua@emaildefense.proofpoint.com;ruf=mailto:caixa-bank@ruf.agari.com,mailto:dmarc_ruf@emaildefense.proofpoint.compolicy: reject (enforced) - DKIM
-
- google:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAzadXq3B6Erj3W8HYeL15odQohKhHI+2EcQaVnVXQAsQTpLKhZcOIroD4PF39kB18u0QVg6vAfMhufV…
selectors probed - google:
Certificate (current)
COMODO RSA Organization Validation Secure Server CA
Expires in 141 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
frame-ancestors 'self';block-all-mixed-content;default-src 'self';script-src 'self' 'report-sample' 'unsafe-inline' 'unsafe-eval' code.jquery.com googletagmanager.com tagmanager.google.com www.googletagmanager.com www.google-analytics.com *.google.com *.gstatic.com;style-src 'self' 'report-sample' 'unsafe-inline' fonts.googleapis.com tagmanager.google.com www.googletagmanager.com;object-src 'none';frame-src 'self' *.googletagmanager.com *.vimeo.com *.youtube.com *.google.com *.gstatic.com;child-src 'self' www.googletagmanager.com *.google.com *.gstatic.com;img-src 'self' cdn.n1ed.com i.vimeocdn.com www.google-analytics.com *.google.es *.analytics.google.com *.doubleclick.net *.wonnowawards.com *.google.com *.gstatic.com data: fonts.gstatic.com www.googletagmanager.com;font-src 'self' data: fonts.googleapis.com fonts.gstatic.com;connect-src 'self' fonts.googleapis.com fonts.gstatic.com www.googletagmanager.com *.google-analytics.com *.analytics.google.com *.doubleclick.net;manifest-sr- strict-transport-security
max-age=31536000; includeSubDomains