Información Técnica
| Código de estado HTTP | 200 |
| Versión HTTP | HTTP/1.1 |
| HTTPS | ✔ Disponible |
| Dirección IP | 44.230.115.150 |
| Software del servidor | envoy |
| CDN | CDN (MISS) |
| Compresión | gzip |
|
ℹ 🔵 Falta X-Frame-Options | El sitio puede ser incrustado en iframes por terceros (riesgo de clickjacking). |
Código de estado HTTP 200
Versión HTTP HTTP/1.1
HTTPS ✔ Disponible
Dirección IP 44.230.115.150
Software del servidor envoy
CDN CDN (MISS)
Compresión gzip
ℹ 🔵 Falta X-Frame-Options El sitio puede ser incrustado en iframes por terceros (riesgo de clickjacking).
Cadena de Redirecciones
| # | URL | Código de estado HTTP | Estado |
| 1 | https://spoti.fi:443 | 307 | HTTP/1.1 307 Temporary Redirect |
| 2 | https://open.spotify.com/ | 200 | HTTP/2 200 |
#1 URL https://spoti.fi:443
Código de estado HTTP 307
Estado HTTP/1.1 307 Temporary Redirect
#2 URL https://open.spotify.com/
Código de estado HTTP 200
Estado HTTP/2 200
Rendimiento
| Resolución DNS | 2.2 ms |
| Conexión TCP | 3 ms |
| Negociación TLS | 3.7 ms |
| Tiempo hasta el primer byte (TTFB) | 57.1 ms |
| Descarga de contenido | 2.5 ms |
| Tiempo total de respuesta | 59.6 ms |
Resolución DNS 2.2 ms
Conexión TCP 3 ms
Negociación TLS 3.7 ms
Tiempo hasta el primer byte (TTFB) 57.1 ms
Descarga de contenido 2.5 ms
Tiempo total de respuesta 59.6 ms
Seguridad
| HTTPS | ✔ Activado |
| HSTS | ✔ max-age=31536000 |
| CSP | ✔ Configurado |
| X-Frame-Options | ⚠ No configurado |
| X-Content-Type-Options | ✔ nosniff |
| HTTP/2 | ⚠ HTTP/1.1 |
HTTPS ✔ Activado
HSTS ✔ max-age=31536000
CSP ✔ Configurado
X-Frame-Options ⚠ No configurado
X-Content-Type-Options ✔ nosniff
HTTP/2 ⚠ HTTP/1.1
Comprobación SEO
| Título | Spotify – Web Player |
| Canonical | https://open.spotify.com/ |
Título Spotify – Web Player
Canonical https://open.spotify.com/
Tecnologías Detectadas
| Tecnología | Google Analytics Google Tag Manager Hotjar |
Tecnología Google Analytics Google Tag Manager Hotjar
Cabeceras HTTP
| Set-cookie
| sp_landing=https%3A%2F%2Fopen.spotify.com%2F; Max-Age=86400; Path=/; Domain=.spotify.com; HttpOnly; Secure |
| Content-security-policy
| script-src 'self' 'unsafe-eval' blob: open.spotifycdn.com open-review.spotifycdn.com quicksilver.scdn.co www.google-analytics.com www.googletagmanager.com static.ads-twitter.com analytics.twitter.com s.pinimg.com sc-static.net https://www.google.com/recaptcha/ cdn.ravenjs.com connect.facebook.net www.gstatic.com sb.scorecardresearch.com pixel-static.spotify.com cdn.cookielaw.org geolocation.onetrust.com www.fastly-insights.com static.hotjar.com script.hotjar.com https://www.googleadservices.com/pagead/conversion_async.js https://www.googleadservices.com/pagead/conversion/ https://analytics.tiktok.com/i18n/pixel/sdk.js https://analytics.tiktok.com/i18n/pixel/identify.js https://analytics.tiktok.com/i18n/pixel/config.js https://www.redditstatic.com/ads/pixel.js https://t.contentsquare.net/uxa/22f14577e19f3.js https://get.microsoft.com/badge/ms-store-badge.bundled.js https://cdn.us.heap-api.com https://heapanalytics.com 'sha256-WfsTi7oVogdF9vq5d14s2birjvCglqWF842fyHhzoNw=' 'sha256-KRzjHxCdT8icNaDOqPBdY0AlKiIh5F8r4bnbe1PQwss=' 'sha256-Z5wh7XXSBR1+mTxLSPFhywCZJt77+uP1GikAgPIsu2s=' 'sha256-o2wzIImHJ4+WWE5DCTR+myWU0UNml0+wwpDXRo++vII='; frame-ancestors 'self' https://adgen-dev.spotify.com/account/*/ad/*/details https://adgen-dev.spotify.com/preview/* https://local.spotify.net/account/*/ad/*/details https://local.spotify.net/preview/* https://app.smartly.io/*; |
| Content-type
| text/html; charset=utf-8 |
| X-spotify-open-index
| true |
| X-envoy-upstream-service-time
| 24 |
| Server
| envoy |
| Via
| HTTP/1.1 fringe, HTTP/2 edgeproxy, 1.1 google, 1.1 varnish |
| Strict-transport-security
| max-age=31536000 |
| X-content-type-options
| nosniff |
| Content-encoding
| gzip |
| Accept-ranges
| bytes |
| Date
| Fri, 28 Aug 2026 07:07:58 GMT |
| X-served-by
| cache-par-lfpg1960035-PAR |
| X-cache
| MISS |
| X-cache-hits
| 0 |
| X-timer
| S1787900879.649698,VS0,VE49 |
| Vary
| Accept-Encoding |
Meta Tags
| X-UA-Compatible | IE=9 |
| Viewport | width=device-width, initial-scale=1, maximum-scale=1 |
| Fb:app_id | 174829003346 |
Set-cookie sp_landing=https%3A%2F%2Fopen.spotify.com%2F; Max-Age=86400; Path=/; Domain=.spotify.com; HttpOnly; Secure
Content-security-policy script-src 'self' 'unsafe-eval' blob: open.spotifycdn.com open-review.spotifycdn.com quicksilver.scdn.co www.google-analytics.com www.googletagmanager.com static.ads-twitter.com analytics.twitter.com s.pinimg.com sc-static.net https://www.google.com/recaptcha/ cdn.ravenjs.com connect.facebook.net www.gstatic.com sb.scorecardresearch.com pixel-static.spotify.com cdn.cookielaw.org geolocation.onetrust.com www.fastly-insights.com static.hotjar.com script.hotjar.com https://www.googleadservices.com/pagead/conversion_async.js https://www.googleadservices.com/pagead/conversion/ https://analytics.tiktok.com/i18n/pixel/sdk.js https://analytics.tiktok.com/i18n/pixel/identify.js https://analytics.tiktok.com/i18n/pixel/config.js https://www.redditstatic.com/ads/pixel.js https://t.contentsquare.net/uxa/22f14577e19f3.js https://get.microsoft.com/badge/ms-store-badge.bundled.js https://cdn.us.heap-api.com https://heapanalytics.com 'sha256-WfsTi7oVogdF9vq5d14s2birjvCglqWF842fyHhzoNw=' 'sha256-KRzjHxCdT8icNaDOqPBdY0AlKiIh5F8r4bnbe1PQwss=' 'sha256-Z5wh7XXSBR1+mTxLSPFhywCZJt77+uP1GikAgPIsu2s=' 'sha256-o2wzIImHJ4+WWE5DCTR+myWU0UNml0+wwpDXRo++vII='; frame-ancestors 'self' https://adgen-dev.spotify.com/account/*/ad/*/details https://adgen-dev.spotify.com/preview/* https://local.spotify.net/account/*/ad/*/details https://local.spotify.net/preview/* https://app.smartly.io/*;
Content-type text/html; charset=utf-8
X-spotify-open-index true
X-envoy-upstream-service-time 24
Server envoy
Via HTTP/1.1 fringe, HTTP/2 edgeproxy, 1.1 google, 1.1 varnish
Strict-transport-security max-age=31536000
X-content-type-options nosniff
Content-encoding gzip
Accept-ranges bytes
Date Fri, 28 Aug 2026 07:07:58 GMT
X-served-by cache-par-lfpg1960035-PAR
X-cache MISS
X-cache-hits 0
X-timer S1787900879.649698,VS0,VE49
Vary Accept-Encoding