gabinet.gov.pl
HTML metadata
Technology
- Fonts
-
- Google Fonts
Third-party hosts loaded (1)
- fonts.gstatic.com×1
DNS records live
- NS
-
- cuw1.plus.pl
- dns1.virtuaoperator.pl
- ns1.cez.gov.pl
- ns2.cez.gov.pl
- TXT
-
Show 4 TXT records
1a756317218ef2dff739b7bd0a62376762cd4bac38439f6663804b5f9fd5797mojecertpl-site-verification-oKoJ5AsZzGR5V9u4lnFt6cL59HDdskIq0k5hsym1c8htdmd5fswl2q5tpmhw2b2gb8dad86da078fef99d592b9fbd3e0f0695e1a7b3b06e84846814b5c952df3a0
Email authentication no MX
- SPF
-
v=spf1 -allstrict (-all) - DMARC
-
v=DMARC1;p=reject;adkim=s;aspf=s;rua=mailto:dmarc@cez.gov.plpolicy: reject (enforced) - DKIM
- no key found at common selectors
Certificate (current)
Certum OV TLS G2 R39 CA
Expires in 236 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src 'self'; img-src https://www.google-analytics.com 'self' data: blob:; script-src 'self' https://www.google-analytics.com/analytics.js https://www.googletagmanager.com 'unsafe-inline' https://www.elektronicznypodpis.pl https://chrome.google.com https://addons.opera.com 'unsafe-eval' */pdf.js */viewer.js blob:; connect-src 'self' blob: data:; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com; font-src 'self' https://fonts.gstatic.com data:; child-src 'self' blob: https: http:; object-src 'none';- strict-transport-security
max-age=16070400; includeSubDomains