face.gob.es
CFACe
Built with
- Frontend framework
- Vue.js
Also detected
- Libraries
- jQuery
- Infrastructure
- IIS
- Third-party services
- Matomo
Overview
- Status
- alive
- Registered
- unknown (this domain's registry doesn't publish it via RDAP)
- First seen here
- 2026-09-22
- Security grade
- C (70/100, from headers & TLS)
- Privacy score
- 76/100 (1 third-party script hosts, 1 tracking/marketing services)
- Hosting
- Ministerio De Economia, Comercio Y Empresa · AS200521 · Spain
- Server header
Microsoft-IIS/5.0- Response time
- 554 ms to first byte, measured from our crawler
- TLS certificate
- FNMT-RCM · TLSv1.2 · expires 2027-03-15
- Mobile-ready
- no viewport meta tag
- Linked to from
- 1 other sites seen so far
Loads scripts from
Third-party domains this page pulls JavaScript or iframes from. Each one can see who visits.
google.com
What to fix
- Add a Content-Security-Policy
Limits which scripts can run, and is the main defense against XSS. Start with Content-Security-Policy-Report-Only to test. - Mark cookies Secure and HttpOnly
At least one cookie is sent without these flags, exposing it to interception or scripts. - Publish an SPF record
A DNS TXT record listing who may send email for this domain, which prevents spoofing. - Publish a DMARC record
A TXT record at _dmarc.<domain>; start with v=DMARC1; p=none; to monitor. - Add a viewport meta tag
<meta name="viewport" content="width=device-width, initial-scale=1">. Without it, the site renders badly on phones.
Security & email signals
- ✓ HTTPS
- ✓ HSTS
- ✗ Content-Security-Policy
- ✓ X-Content-Type-Options
- ✓ X-Frame-Options
- ✓ Referrer-Policy
- ✗ Permissions-Policy
- ✗ SPF record
- ✗ DMARC record
- ✗ DKIM record
- ✗ Cookies set securely
- ✓ Has real content (not an empty shell)
- ✓ Valid TLS certificate
Badge
Show this site's security grade in a README or footer:

<a href="https://webtelemetry.dev/site/face.gob.es"><img src="https://webtelemetry.dev/badge/face.gob.es.svg" alt="Security grade"></a>
Generated automatically from passive, publicly observable data. Think something here is wrong or want this profile removed? See /bot. Machine-readable: JSON.