chopincompetition.pl
HTML metadata
Technology
- Server
- Apache
- CMS
- Next.js
- Analytics
-
- Google Tag Manager
Third-party hosts loaded (1)
- www.googletagmanager.com×1
DNS records live
- NS
-
- dns.home.pl
- dns2.home.pl
- dns3.home.pl
- MX
-
- 0 mx.host.nask.pl
Email authentication weak
- SPF
-
v=spf1 include:_spf.mlsend.com ip4:195.187.250.240 a mx include:_spf.poczta.host.nask.pl -allstrict (-all) - DMARC
- not published
- DKIM
- no key found at common selectors
Certificate (current)
E8
Expires in 35 days
HTTP security headers
- present
-
- content-security-policy
- findings
-
- missing HSTS
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing frame protection
- missing content type protection
- missing Referrer Policy
- missing Permissions Policy
Header values
- content-security-policy
default-src 'self'; script-src 'self' 'unsafe-eval' 'unsafe-inline' https://va.vercel-scripts.com https://vercel.live https://cdn.jsdelivr.net https://www.googletagmanager.com https://*.redcdn.pl https://r.dcs.redcdn.pl https://n-115-5.dcs.redcdn.pl/file/o2/web/player/redcdn/3.5.0/js/redgalaxy-player-3.5.0.min.js https://connect.facebook.net https://googleads.g.doubleclick.net https://www.googleadservices.com; style-src 'self' 'unsafe-inline' https://*.redcdn.pl https://www.googletagmanager.com https://fonts.googleapis.com; img-src 'self' blob: data: https://publikacje.nifc.pl https://storage.nifc.pl https://mqwdhbc9syq4so2b.public.blob.vercel-storage.com www.googletagmanager.com https://*.redcdn.pl https://www.google.pl https://www.google.com https://www.facebook.com https://pagead2.googlesyndication.com; media-src 'self' blob: https://r.dcs.redcdn.pl https://*.dcs.redcdn.pl https://storage.nifc.pl; worker-src 'self' blob:; font-src 'self' data: https://*.redcdn.pl; object-src 'self';
Links to (2)
- www.gov.pl×1
- nifc.pl×1