ding.pl
HTML metadata
Technology
- Server
- nginx
- Fonts
-
- Google Fonts
Third-party hosts loaded (6)
- i.iplsc.com×101
- p.iplsc.com×12
- api.gazetkapromocyjna.pl×1
- fonts.gstatic.com×1
- js.iplsc.com×1
- prywatnosc.interia.pl×1
Social
DNS records live
- NS
-
- dns1.interia.pl
- dns2.interia.pl
- dns3.interia.pl
- MX
-
- 10 mx3.plus.pl
- 10 mx4.plus.pl
- Verified for
-
- Meta
- Microsoft 365
Email authentication weak
- SPF
-
v=spf1 a mx ptr ip4:217.74.64.0/22 ip4:80.48.65.0/24 ip4:217.74.75.180 ip4:217.74.75.181 ip4:185.69.192.148 ip4:212.2.119.142/31 include:spf.protection.outlook.com a:mailing-out.htp.interia.pl -allstrict (-all) - DMARC
- not published
- DKIM
-
- mail:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCjg676ru95OCthEU4MZk0+tJ9AHECtpyivXsadzeYfvtJtB5cI+ZrKPcrAEeMmnaa9EQhUQRAJ+ujO2Fm6nV…
selectors probed - mail:
Certificate (current)
home pl DV TLS G2 R35 CA
Expires in 194 days
HTTP security headers
- present
-
- content-security-policy
- referrer-policy
- permissions-policy
- cross-origin-opener-policy
- cross-origin-embedder-policy
- cross-origin-resource-policy
- findings
-
- missing HSTS
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing frame protection
- missing content type protection
Header values
- referrer-policy
origin- permissions-policy
encrypted-media=(), microphone=(), midi=()- content-security-policy
default-src * 'unsafe-inline' 'unsafe-eval'; script-src * 'unsafe-inline' 'unsafe-eval'; connect-src * 'unsafe-inline'; img-src * data: blob: 'unsafe-inline'; frame-src *; style-src * 'unsafe-inline'; font-src 'self' fonts.gstatic.com data:;- cross-origin-opener-policy
unsafe-none; report-to=default- cross-origin-embedder-policy
unsafe-none; report-to=default- cross-origin-resource-policy
cross-origin