castorama.pl
HTML metadata
Technology
- CDN
- Amazon CloudFront
- Server
- CloudFront
- CMS
- Gatsby
Third-party hosts loaded (5)
- s7g10.scene7.com×79
- ccl-prod.cache.ap.digikfplc.com×15
- consent.truste.com×1
- eu2.flavedo.io×1
- tags.tiqcdn.com×1
Social
DNS records live
- NS
-
- ns-1500.awsdns-59.org
- ns-2015.awsdns-59.co.uk
- ns-304.awsdns-38.com
- ns-764.awsdns-31.net
- MX
-
- 0 castorama-pl.mail.protection.outlook.com
- TXT
-
Show 9 TXT records
dSnxnp9P6kjDRkwJzOlUAWJXMPP9d7M3KJOqTfZRaSY=oMY39NZ9gYXHswtDkSlpXqzUUbiyYuwo/6ygrtq+qjs=rovag_verification_token=E4AEF523FF814BB9920FACF4780CA2FAsending_domain953423=08fca1787dfcd64a4d3234684d7c8e46b2b4b733caea99cdea7de776f3d4cbb5sj8xqqmfxrw7fw3snbstz86043bp66x09rtv2z38549ch2yg1v2q4q0p5pnsxm6pMslqJZwwPVxBfzjucETHGqg9MdIKtLYAQtKDqgNBAUk=_7oi081ux74ywej34mx3243nf1ys0vxn_cl9jzds7klr98v9kk4pxyzay6adiucl
- Verified for
-
- Atlassian
- GlobalSign
- Microsoft 365
- Miro
- Yahoo
Email authentication strong
- SPF
-
v=spf1 ip4:202.22.171.122 ip4:83.166.79.128 ip4:178.216.203.75 ip4:192.0.2.10 ip4:198.51.100.25 include:spf.protection.outlook.com include:manago360.com include:_spf.mail03-userengage.com include:staticip.castorama.pl include:spf.tipimail.com include:_spf.salesforce.com -allstrict (-all) - DMARC
-
v=DMARC1; p=reject; rua=mailto:102b7a32a370252@rep.dmarcanalyzer.com; ruf=mailto:102b7a32a370252@for.dmarcanalyzer.com; fo=1;policy: reject (enforced) - DKIM
-
Show 5 DKIM selectors
- selector1:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAl0nciv+refOK40j/C0wS0ryodgUsi0GU/AdWMAoovQs1wNz7LXQHHmzypGvVba1PNFsY9mw0SZ76eW… - selector2:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA09SESw0wb7NVYB8PzATNxCOK3mTYGdMAYiTmZc5YDuw88Kb3iwYXhO7+sBHGSFbzyARzhBk5B0wVRO… - mail:
v=DKIM1; h=sha256; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA9vy7JxQAZjOWVJhgyp9AZXEMG78UNpbaDmMVysMPD6rxT+0MjLATjawVfohxNY59BOOz… - s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAuBkIs7Y3798NMcVSyPdot6ZurEjR7S3+/ugqfHyptA9M3fAxECBU2YF9XzbBA3anXl9+rg6t8Mqscdzq6r… - s2:
k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCRDQUedQCRrQWscy1F85u37XV30Y39ojLftq51HVKzntIj0+hPk33zaMSTj6gorE+PyIe6K7S1zZrwTYyrlVuzFv…
selectors probed - selector1:
Certificate (current)
GlobalSign GCC R3 EV TLS CA 2025
Expires in 294 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src * 'unsafe-inline' 'unsafe-eval' ; child-src blob: ; worker-src 'self' blob: ; script-src * 'unsafe-inline' 'unsafe-eval' ; connect-src * ; media-src * ; img-src * data: blob: ; frame-src * ; frame-ancestors 'self' https://castorama-poland-sandbox.citrusad.com https://castorama-poland.citrusad.com ; style-src * data: 'unsafe-inline' ; font-src * data: ;- strict-transport-security
max-age=31536000; includeSubdomains; preload