Technical Information
| HTTP Status Code | 403 |
| HTTP Version | HTTP/1.1 |
| HTTPS | ✔ Available |
| IP Address | 185.246.52.108 |
| Compression | gzip |
|
🚫 🟡 HTTP 403 Error | The server returned a 403 error. Check the access configuration. |
|
ℹ 🔵 Missing Content Security Policy | CSP is not configured. It helps prevent XSS attacks and content injection. |
|
ℹ 🔵 Missing X-Frame-Options | The site can be embedded in iframes by third parties (clickjacking risk). |
HTTP Status Code 403
HTTP Version HTTP/1.1
HTTPS ✔ Available
IP Address 185.246.52.108
Compression gzip
🚫 🟡 HTTP 403 Error The server returned a 403 error. Check the access configuration.
ℹ 🔵 Missing Content Security Policy CSP is not configured. It helps prevent XSS attacks and content injection.
ℹ 🔵 Missing X-Frame-Options The site can be embedded in iframes by third parties (clickjacking risk).
Performance
| DNS Lookup | 17.6 ms |
| TCP Connect | 34.1 ms |
| TLS Handshake | 21.6 ms |
| Time To First Byte (TTFB) | 80.1 ms |
| Content Download | 1.8 ms |
| Total Response Time | 81.9 ms |
DNS Lookup 17.6 ms
TCP Connect 34.1 ms
TLS Handshake 21.6 ms
Time To First Byte (TTFB) 80.1 ms
Content Download 1.8 ms
Total Response Time 81.9 ms
Security
| HTTPS | ✔ Enabled |
| HSTS | ✔ max-age=15552000; includeSubdomains |
| CSP | ⚠ Not configured |
| X-Frame-Options | ⚠ Not configured |
| X-Content-Type-Options | ⚠ Not configured |
| HTTP/2 | ⚠ HTTP/1.1 |
HTTPS ✔ Enabled
HSTS ✔ max-age=15552000; includeSubdomains
CSP ⚠ Not configured
X-Frame-Options ⚠ Not configured
X-Content-Type-Options ⚠ Not configured
HTTP/2 ⚠ HTTP/1.1
SEO Quick Check
| Title | Access denied | www.march.es uses SysAdminOK WAF to restrict malicious requests |
Title Access denied | www.march.es uses SysAdminOK WAF to restrict malicious requests
Detected Technologies
| Technology | Google Analytics |
Technology Google Analytics
HTTP Headers
| Date | Fri, 24 Jul 2026 17:02:35 GMT |
| Content-type | text/html |
| Strict-transport-security | max-age=15552000; includeSubdomains |
| Access-control-allow-credentials | true |
| Access-control-allow-methods | GET,HEAD,POST,PATCH,DELETE |
| Access-control-allow-headers | DNT,X-CustomHeader,Keep-Alive,User-Agent,X-Requested-With,If-Modified-Since,Cache-Control,Content-Type,Authorization,Origin,X-CSRFToken,Content-Language,Accept-Language,X-Access-Token,X-User-Agent,X-Access-Signature |
| Content-encoding | gzip |
Meta Tags
| Content-Type | text/html; charset=UTF-8 |
| X-UA-COMPATIBLE | IE=edge |
| Waf_id | 4814aca206fb8a8fcbe473275457fae7 |
Date Fri, 24 Jul 2026 17:02:35 GMT
Content-type text/html
Strict-transport-security max-age=15552000; includeSubdomains
Access-control-allow-credentials true
Access-control-allow-methods GET,HEAD,POST,PATCH,DELETE
Access-control-allow-headers DNT,X-CustomHeader,Keep-Alive,User-Agent,X-Requested-With,If-Modified-Since,Cache-Control,Content-Type,Authorization,Origin,X-CSRFToken,Content-Language,Accept-Language,X-Access-Token,X-User-Agent,X-Access-Signature
Content-encoding gzip