Studies / S8
What can a machine verify on Spain's public-sector websites?
Abstract
Some obligations and good practices for public websites leave a trace a program can check without judgement: a security.txt file (RFC 9116), an accessibility statement linked from the site and "actualizada periódicamente, como mínimo una vez al año" (Royal Decree 1112/2018, art. 15.1), HTTPS with HSTS, and a stated policy towards AI crawlers. We checked them on the websites of 6,648 of Spain's 8,132 municipalities (81.8% of municipalities, 98.9% of the population) and on the 19 regional governments, 52 provincial and island councils, 50 public universities and 22 ministries. Of 6,730 entities whose home page we could measure, 5,245 (77.9%) returned their own home page; 179 municipal URLs led to something that is not the council's site (hijacked or parked domains, hosting panels). Of the 5,245, 5,130 (97.8%) served the home page over HTTPS when asked, but 1,688 of those 5,130 (32.9%) send HSTS. **Of 5,570 entities whose server answered for /.well-known/security.txt, 12 serve a file, 8 have its required fields and 4 are strictly valid under RFC 9116, while 329 (5.9%) answer that path with HTTP 200 and something else. 2,492 of 5,245 home pages (47.5%) carry a link to the accessibility statement that our detector can see; of 1,247 statements read with an audited date extractor, 908 (72.8%) show a preparation or review date and 160 (12.8%) show one from the last 365 days**. Spain's official monitoring already checks, by experts on a sample of about 63 websites a year, whether a statement is provided and what it says; it does not report whether home pages link to it or how old its date is, which is what this census adds. The six most frequent dates each occur in a single province and cover 479 of the 908 dated statements (52.8%), which points to statements produced in bulk for many municipalities at once; we did not identify by whom. 326 of 6,012 entities (5.4%) block at least one of GPTBot, ClaudeBot, Google-Extended or CCBot, concentrated in a few regions; a spec-like llms.txt appears on 7 of 1,020 sites in a random subsample (0.7%). There is no official national list of municipal websites; the URLs come from Wikidata and one regional directory, and small municipalities are under-covered (3,612 of 4,980 under 1,000 inhabitants, 72.5%, have a known URL). A first version of our scanner fetched the home page of 123 entities, and security.txt, llms.txt or the statement of another 722, although their robots.txt did not allow it; those records were deleted, not used, and the 123 are reported as not measurable. We publish the per-entity table, the cleaned scan records, the scanner and the method, and propose a free tool, gov-web-lint, that any administration could run on its own site.
Cite this study
EasyxLab (2026). What can a machine verify on Spain's public-sector websites? Study S8. EasyByte Hub S. Coop. Mad. https://github.com/easybytehub/easyxlab/tree/main/studies/s8-spanish-public-sector-web@techreport{easyxlab_s8,
title = {What can a machine verify on Spain's public-sector websites?},
author = {{EasyxLab}},
institution = {EasyByte Hub S. Coop. Mad.},
number = {S8},
year = {2026},
url = {https://github.com/easybytehub/easyxlab/tree/main/studies/s8-spanish-public-sector-web}
}