albedomarketing.pl
HTML metadata
Technology
- Server
- Apache
- Ads
-
- Google Ads
- Google Ads (DoubleClick)
Third-party hosts loaded (4)
- cdn.cookie-script.com×1
- googleads.g.doubleclick.net×1
- www.facebook.com×1
- www.googleadservices.com×1
DNS records live
- NS
-
- ns1.aftermarket.pl
- ns2.aftermarket.pl
- MX
-
- 0 albedomarketing-pl.mail.protection.outlook.com
- TXT
-
d564eefbba69b66b92a171bcacf504cd9b992e8ccd5f6c22d5a6be007056265
- Verified for
-
- Anthropic
- Apple
- Atlassian
- Brevo
Email authentication strong
- SPF
-
v=spf1 include:_spf.mlsend.com ip4:213.216.68.99 include:spf.protection.outlook.com -allstrict (-all) - DMARC
-
v=DMARC1; p=reject; rua=mailto:postmaster@albedomarketing.pl; rua=mailto:rua@dmarc.brevo.compolicy: reject (enforced) - DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAntOBrjPExUS+Um4fME9Xl1tkM1B8EvPwFQl92qUjOLP97U5SctPnJIh7PJp5840mpG38zjBdpwYo+2…
selectors probed - selector1:
Certificate (current)
Certum Domain Validation CA SHA2
Expires in 86 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- missing Permissions Policy
Header values
- referrer-policy
same-origin- x-frame-options
DENY- x-content-type-options
nosniff- content-security-policy
default-src 'self' https://www.google-analytics.com/ https://stats.g.doubleclick.net/ https://www.youtube.com/; font-src 'self' https://use.typekit.net/ https://fonts.gstatic.com/ https://p.typekit.net/ https://fonts.googleapis.com/; img-src 'self' https://www.google.com/ https://www.google.pl/ https://i.ytimg.com/ https://www.google-analytics.com/ https://www.facebook.com/ https://cdn.datatables.net/ https://maps.googleapis.com/ https://maps.gstatic.com/ https://cdn.ckeditor.com/ https://www.googletagmanager.com/ data:; script-src 'self' https://connect.facebook.net/ https://www.googleadservices.com/ https://googleads.g.doubleclick.net/ https://code.jquery.com/ https://www.youtube.com/ https://www.google-analytics.com/ https://www.googletagmanager.com/ https://google-analytics.com/ https://cdn.ckeditor.com/ https://cdn.cookie-script.com/ https://www.google.com/ https://www.gstatic.com/ 'unsafe-inline' 'unsafe-eval' https://maps.googleapis.com/ https://cdn.datatables.net/ https://edito- strict-transport-security
max-age=31536000; includeSubDomains