workcapital.es
HTML metadata
Technology
- CDN
- Cloudflare
- CMS
- WordPress
- Analytics
-
- Cloudflare Insights
- Google Tag Manager
Third-party hosts loaded (6)
- cdn-klfgd.nitrocdn.com×48
- cdn.cookie-script.com×1
- gmpg.org×1
- static.cloudflareinsights.com×1
- www.google.com×1
- www.googletagmanager.com×1
Social
Contact
- Phone
- Address
- Plaza Alquería de la Culla, 4 46910
DNS records live
- NS
-
- aria.ns.cloudflare.com
- micah.ns.cloudflare.com
- MX
-
- 1 workcapital-es.mail.protection.outlook.com
- TXT
-
Show 9 TXT records
20200702151207288t6it9hfohj5aaiqc4bq0yh54i0caz1lifz2agdqjlp10tzu202107021612082e0dy04ka0ad8kpz2f60qjt5hjluc032jphtcjyyd9j9ob8kr72022070204425815wcypa1e9pur30v3p6751oaqdjwjpvm2texzjgnolg2xktrbx202307040500561vd1gjgo5u9ot2xlj28ac2vcey3j3atbmeyu1vvuz36v1bveh32024081703462808mdf2d18ciyg9yali8iv2c7v74n3h43vr6p9jhocbus3fsvau971c4m1bl3u95b63fnsd0gqcedbrevo-code:225e04f7b0af1dfdbb0c085e4bcc4183google-site-verification=WA6x3GYlkDvDdwkZwxWI14ijI_qE85Ubc4j9EbBOnd4ppe-3fc4e2fffcaac7012e9ede2e68d584fe494a7a5b
Email authentication strong
- SPF
-
v=spf1 include:spf.protection.outlook.com include:spf.mandrillapp.com include:147471976.spf04.hubspotemail.net ip4:217.76.142.73 ip4:5.196.197.248 ip4:185.47.13.11 -allstrict (-all) - DMARC
-
v=DMARC1; p=reject; rua=mailto:d54fd6d8c18d412294c18551a1fc213a@dmarc-reports.cloudflare.net,mailto:dmarc-rua@workcapital.es; ruf=mailto:dmarc-ruf@workcapital.es;policy: reject (enforced) - DKIM
-
- selector2:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDDMnDSSZM2Vc0Igs2ajNVc4WGqAOvVrF2Sv8yxDWgaPC4/fsMRZDz/3q7We//70ItrEsxjQo6DW4indEu0Ps…
selectors probed - selector2:
Certificate (current)
WE1
Expires in 67 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-content-type-options
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing frame protection
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-content-type-options
nosniff- content-security-policy
default-src 'self' https:; script-src 'self' 'unsafe-inline' 'unsafe-eval' blob: https: *.nitropack.io *.nitrocdn.com; style-src 'self' 'unsafe-inline' https: *.nitropack.io *.nitrocdn.com; img-src 'self' data: blob: https: *.nitropack.io *.nitrocdn.com; font-src 'self' https: data: *.nitropack.io *.nitrocdn.com; connect-src 'self' https: *.nitropack.io *.nitrocdn.com api.whatsapp.com; frame-src https: *.nitropack.io *.nitrocdn.com www.youtube.com www.facebook.com es.linkedin.com twitter.com www.boe.es; worker-src 'self' blob: https: *.nitropack.io *.nitrocdn.com; base-uri 'self'; form-action 'self' https:; frame-ancestors 'self'; object-src 'none';- strict-transport-security
max-age=31536000; includeSubDomains
Links to (7)
- boe.es×1
- facebook.com×1
- linkedin.com×1
- miteco.gob.es×1
- twitter.com×1
- whatsapp.com×1
- youtube.com×1
Linked from (1)
- febf.org×1