fleksi.cz
HTML metadata
Technology
- Server
- Microsoft-IIS
- CMS
- Next.js
- JS framework
- Next.js
- Fonts
-
- Google Fonts
Third-party hosts loaded (8)
- code.archilogic.com×3
- cdnjs.cloudflare.com×2
- fonts.gstatic.com×2
- cdn.jsdelivr.net×1
- fonts.googleapis.com×1
- js.stripe.com×1
- maps.googleapis.com×1
- unpkg.com×1
DNS records live
- NS
-
- alfa.ns.active24.cz
- beta.ns.active24.cz
- gama.ns.active24.sk
- MX
-
- 10 antispam2.passerinvest.com
- 5 antispam1.pstgrp.cz
- Verified for
-
- Microsoft 365
Email authentication weak
- SPF
-
v=spf1 mx include:_spf.pstgrp.cz ip4:31.15.10.150 ip4:193.86.92.230/31 ip4:193.86.92.232/31 ip4:212.24.139.248/29 ip4:95.80.234.32/29 ip4:193.86.92.240/30 ip4:193.86.92.239/32 ip4:193.86.92.242/32 ip4:193.86.92.244/31 ip4:193.86.92.245/32 ip4:213.151.91.168/29 ip4:85.132.182.80/28 -allstrict (-all) - DMARC
- not published
- DKIM
- no key found at common selectors
Certificate (current)
E7
Expires in 30 days
HTTP security headers
- present
-
- content-security-policy
- x-content-type-options
- findings
-
- missing HSTS
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing frame protection
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-content-type-options
nosniff- content-security-policy
default-src 'self' ; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://*.facebook.net https://*.facebook.com https://*.cloudfront.net https://*.datadoghq-browser-agent.com https://*.nexudus.com https://*.doubleclick.net https://maps.googleapis.com https://*.archilogic.com https://*.stripe.com https://*.forte.net https://*.midtrans.com https://*.spreedly.com https://*.klarnacdn.net https://*.braintreegateway.com https://*.cloudflare.com https://unpkg.com/ https://recaptcha.net/recaptcha/ https://www.gstatic.com/recaptcha/ http://platform.twitter.com https://*.googletagmanager.com https://*.youtube.com https://*.amazonaws.com/ https://*.razorpay.com https://snap.licdn.com https://www.gstatic.com https://static.hotjar.com https://www.google-analytics.com https://sc.lfeeder.com https://bat.bing.com/bat.js https://cdn.cookie-script.com https://cdn-cookieyes.com 'self' https://fleksinetwork.spaces.nexudus.com https://snap.licdn.com/ https://c.seznam.cz/ https://www.fleksi.cz/ https://c