carollinum.cz
HTML metadata
Technology
- Server
- nginx
- CMS
- Gatsby
- Fonts
-
- Google Fonts
Third-party hosts loaded (4)
- carollinum.b-cdn.net×63
- fonts.googleapis.com×3
- fonts.gstatic.com×1
- static.rolex.com×1
Social
DNS records live
- NS
-
- ns.gransy.com
- ns2.gransy.com
- ns3.gransy.com
- ns4.gransy.com
- ns5.gransy.com
- MX
-
- 0 carollinum-cz.mail.protection.outlook.com
- TXT
-
Show 6 TXT records
d9v4vjlp6zzct2wvl02bzltkn1jnpw5n_ns2omq99hfk27edawcg9jvdwutjifgaf0fk249pkw0s4wlscy4gdnlv4rmv4sm6/K1Bu5L6CDCVEHT9DiNeZGvHKWqNhH6NfQrHgETvTd4uUZ/Z0SonpRno886HwGkgdfz8WKpBsNPLmsfyokUh3w==v02srbt92p3lqd2lk0060fqqtbl69s55ppe-5919993e35c294eda1eba4a3114aac49b37b6c59
- Verified for
-
- Microsoft 365
Email authentication partial
- SPF
-
v=spf1 mx include:spf-zoner-cloudmail.zoner.com include:spf.protection.outlook.com include:smtpout.com include:spf.mtaroutes.com include:servers.mcsv.net ip4:193.86.188.11 ip4:90.182.97.123 ip4:51.145.226.204 ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=none;policy: none (monitoring only) - DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDNFCId/SsuV7ikrbRdJ/RwESrqwERgHsWVxFZ1aTbJxKI6QA9Spr1kH+vw/yYS7am7h/lWe4algIfbpHAZ4x… - k2:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAv2aC2KjGKLOwTweBY5A9RpjsxaBXR9r7OAU6U8/zn92ivImI75naUujWbItRI/QmL1jy5PWGqLwoUA…
selectors probed - selector1:
Certificate (current)
E8
Expires in 46 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN- permissions-policy
accelerometer=(), autoplay=(), camera=(), cross-origin-isolated=(), display-capture=(), encrypted-media=(), geolocation=(), gyroscope=(), keyboard-map=(), magnetometer=(), microphone=(), midi=(), payment=(), picture-in-picture=(), publickey-credentials-get=(), screen-wake-lock=(), sync-xhr=(self), usb=(), web-share=(), xr-spatial-tracking=(), gamepad=(), hid=(), idle-detection=(), interest-cohort=(), serial=(), unload=(self)- x-content-type-options
nosniff- content-security-policy
script-src 'self' 'unsafe-inline' 'unsafe-eval' https://localhost:* *.googletagmanager.com *.google-analytics.com; script-src-elem 'unsafe-inline' http://vite.localhost:* https://localhost:* https://dev1.carollinum2.client.puxdesign.cz https://www.carollinum.cz https://carollinum-test.b-cdn.net https://carollinum.b-cdn.net https://cdn.puxdesign.cz https://assets.adobedtm.com https://rolex.demdex.net https://clock.rolex.com https://cm.everesttech.net https://smetrics.rolex.com https://static.rolex.com https://cornersv7.rolex.com https://iframe.patek.com *.googletagmanager.com https://c.seznam.cz *.google-analytics.com *.hotjar.com *.adform.net *.smartlook.com *.googleapis.com *.smartform.cz https://www.youtube.com https://www.google.com https://www.gstatic.com https://www.facebook.com https://connect.facebook.net https://www.clarity.ms https://c.clarity.ms https://scripts.clarity.ms https://ss.carollinum.cz https://stapecdn.com https://capi-automation.s3.us-east-2.amazonaws.com; worker-- strict-transport-security
max-age=31536000;includeSubDomains