budinpestoun.cz
HTML metadata
Technology
- CDN
- Azure Front Door
- Stack
- Java
Social
DNS records live
- NS
-
- gate.mpsv.cz
- ns2.mpsv.cz
Email authentication no MX
- SPF
- not published
- DMARC
- not published
- DKIM
- no key found at common selectors
Certificate (current)
Thawte TLS RSA CA G1
Expires in 243 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
origin-when-cross-origin- x-frame-options
SAMEORIGIN- permissions-policy
geolocation=(), microphone=(), camera=()- x-content-type-options
nosniff- content-security-policy
default-src 'self' https://mpsv.gov.cz https://data.mpsv.cz https://*.google-analytics.com https://stats.g.doubleclick.net/ https://mapserver.mapy.cz https://api.mapy.cz https://*.mpsv.cz wss://*.mpsv.cz https://pomoc.mluvii.com wss://pomoc.mluvii.com wss://ws.hotjar.com/ https://*.hotjar.io/ https://nominatim.openstreetmap.org https://www.google.com; img-src 'self' data: https://*.gstatic.com https://www.google-analytics.com https://api.mapy.cz https://mapserver.mapy.cz https://*.openstreetmap.org https://npmcdn.com; frame-src 'self' formapps: https://www.google.com https://www.youtube.com https://*.predu.sk https://chatbot.mpsv.cz https://chatbot.uradprace.cz https://pomoc.mluvii.com data:; child-src 'self' ; script-src 'self' 'unsafe-inline' 'unsafe-eval' data: https://*.gstatic.com https://api.mapy.cz https://www.google.com https://www.googletagmanager.com/ https://www.google-analytics.com https://*.predu.sk https://chatbot.mpsv.cz https://chatbot.uradprace.cz https://pomoc.mluvii.- strict-transport-security
max-age=31536000; includeSubDomains