badminton-most.cz
HTML metadata
Technology
- Server
- nginx
Third-party hosts loaded (1)
- www.google.com×2
Social
Contact
DNS records live
- NS
-
- ns.onebit.cz
- ns.onebit.eu
- ns.onebit.org
- MX
-
- 0 mx10.onebit.cz
- 10 mx10.onebit.eu
Email authentication strong
- SPF
-
v=spf1 mx include:_spf.onebit.cz ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=reject; rua=mailto:info@badminton-most.cz!5m; ruf=mailto:info@badminton-most.cz; rf=afrf; pct=100policy: reject (enforced) - DKIM
-
- default:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDWM9s4woJfIcdHF3QtXPmiv4AWvIxTH/a7jj6GoXieDXtDabEmA9+i0lO07q5HkYYtaMieZW+4q/JnXFgJ4n…
selectors probed - default:
Certificate (current)
R12
Expires in 25 days
HTTP security headers
- present
-
- content-security-policy
- findings
-
- missing HSTS
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing frame protection
- missing content type protection
- missing Referrer Policy
- missing Permissions Policy
Header values
- content-security-policy
default-src 'self';connect-src 'self' ;font-src 'self' data:;style-src 'self' 'unsafe-inline';script-src 'self' 'nonce-IE6k6MBq/1MEyp5j8+5T3XWz0s14XuNAIZWt7wmclsw=' 'strict-dynamic';script-src-attr 'self' 'unsafe-inline';img-src 'self' data: blob: https://i.ytimg.com *.rajce.idnes.cz;base-uri 'self';form-action 'self';frame-src https://www.youtube.com https://www.google.com https://maps.google.com https://www.badminton-most.cz https://badminton-most.cz;frame-ancestors 'self';manifest-src 'self';object-src 'none';
Links to (8)
- mesto-most.cz×1
- mapy.cz×1
- instagram.com×1
- google.com×1
- facebook.com×1
- czechbadminton.cz×1
- aquadrom.cz×1
- 7.cz×1