bibliotekadrawno.pl

.pl crawl

First seen 2026-05-31 · Last seen 2026-06-01 · ok HTTP/1.1 200 915 ms crawled 2026-06-01

FR · 51.68.147.58 · AS16276 OVH SAS

Reputation 92/100 no dmarc policy

Classifying

HTML metadata

Title
Biblioteka Publiczna w Drawnie
Language
pl
Canonical
https://bibliotekadrawno.pl/

Open Graph

url
https://bibliotekadrawno.pl/
locale
pl_PL
site name
Biblioteka Publiczna w Drawnie

Technology

Server
openresty
Analytics
  • Google Tag Manager

Third-party hosts loaded (2)

  • cms-v2-files.idcom-web.pl×18
  • www.googletagmanager.com×1

Social

Contact

Email
Phone

DNS records live

NS
  • ns1.idcom.pl
  • ns2.idcom.pl
MX
  • 0 smtp.idcom.pl

Email authentication weak

SPF
v=spf1 a mx ip4:145.239.239.65/32 ip4:147.135.199.114/32 ip4:54.38.131.43/32 ip4:54.38.131.44/32 ip4:54.38.131.45/32 ip4:145.239.239.66/32 ip4:145.239.239.64/32 ip4:51.83.149.66/32 ip4:54.38.131.43/32 -all
strict (-all)
DMARC
not published
DKIM
  • default: v=DKIM1; h=sha256; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEApFTYxjGhsnKW//lWjtLO/jtOnO6OmGRw3OOzvIC0VMwcgA8SNBAxUnnlNlOGSU4/EdY5ZUR4jfJ…
selectors probed

Certificate (current)

R12
from 2026-04-25 to 2026-07-24
Expires in 52 days

HTTP security headers

Header hygiene 50/100 Checked live page: https://bibliotekadrawno.pl/

present
  • content-security-policy
  • x-content-type-options
findings
  • missing HSTS
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
  • missing frame protection
  • missing Referrer Policy
  • missing Permissions Policy
Header values
x-content-type-options
nosniff
content-security-policy
base-uri 'self'; connect-src wss://ws.hotjar.com www.google.com stats.g.doubleclick.net analytics.google.com region1.google-analytics.com www.google-analytics.com www.googletagmanager.com *.hotjar.io 'self' *.hotjar.com; default-src 'self'; font-src 'self' fonts.gstatic.com data:; form-action 'self'; frame-ancestors 'self'; frame-src https: 'self'; img-src data: *; media-src *; script-src www.gstatic.com www.google.com 'unsafe-inline' 'self' biletyna.pl *.biletyna.pl www.youtube.com widget.twojapogoda.pl weatherwidget.io www.google-analytics.com *.hotjar.io *.hotjar.com connect.facebook.net www.googletagmanager.com; style-src fonts.googleapis.com 'unsafe-inline' 'self'

Links to (6)

Linked from (2)