biano.cz
HTML metadata
Technology
- Server
- nginx
- CMS
- Gatsby
- Ads
-
- Criteo
Third-party hosts loaded (11)
- www.biano.com×2
- creativecdn.com×1
- gum.criteo.com×1
- www.biano.bg×1
- www.biano.gr×1
- www.biano.hu×1
- www.biano.it×1
- www.biano.nl×1
- www.biano.pt×1
- www.biano.ro×1
- www.biano.sk×1
Social
Registration
- Registrar
- REG-WEBGLOBE
- Created
- 2015-03-24
- Expires
- 2029-03-23 1026 days left
- Updated
- 2022-11-05
- Name servers
-
- ns.stable.cz
- ns.stable.sk
DNS records live
- NS
-
- ns.stable.cz
- ns.stable.sk
- MX
-
- 10 mx.stable.sk
- 5 mx.stable.cz
- Verified for
-
- 1Password
- Meta
Email authentication partial
- SPF
-
v=spf1 a mx include:smtpx.stable.cz include:_spf.quanti.cz include:_spf.mail4eshop.com include:amazonses.com include:9480727.spf01.hubspotemail.net ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=none; rua=mailto:info@biano.cz; pct=100; adkim=s; aspf=rpolicy: none (monitoring only) - DKIM
-
- default:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDI/OeTRTCZHU+8y6jigL21FaRcZIg8Kxt6HcWEz9QWBfGCuieTu7lYOMnFUM0MQLcRQPlemCVHCkoMq3qzZY… - k2:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAv2aC2KjGKLOwTweBY5A9RpjsxaBXR9r7OAU6U8/zn92ivImI75naUujWbItRI/QmL1jy5PWGqLwoUA…
selectors probed - default:
Certificate (current)
R13
Expires in 10 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-content-type-options
- referrer-policy
- cross-origin-opener-policy
- cross-origin-resource-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- missing frame protection
- missing Permissions Policy
Header values
- referrer-policy
strict-origin-when-cross-origin- x-content-type-options
nosniff- content-security-policy
default-src 'self';script-src 'self' 'unsafe-inline' 'unsafe-eval' https:;style-src 'self' 'unsafe-inline' https:;img-src 'self' data: blob: https:;media-src 'self' data:;connect-src 'self' data: https: wss:;font-src 'self' data: https:;frame-src 'self' https:;frame-ancestors 'self' https://eshop.biano.cz;worker-src 'self' blob:;report-to csp-endpoint;base-uri 'self';form-action 'self';object-src 'none';script-src-attr 'none';upgrade-insecure-requests- strict-transport-security
max-age=31536000; includeSubDomains- cross-origin-opener-policy
same-origin- cross-origin-resource-policy
same-origin
Links to (7)
- densy.io×1
- facebook.com×1
- instagram.com×1
- linkedin.com×1
- mujadam.cz×1
- startupjobs.cz×1
- youtube.com×1