ingturbo.pl

.pl crawl

First seen 2026-05-27 · Last seen 2026-05-30 · ok HTTP/1.1 200 1250 ms crawled 2026-05-30

NL · 91.220.123.84 · AS39686 Eurofiber Nederland BV

Reputation 94/100 dmarc monitor-only

Classifying

HTML metadata

Title
ING Turbo | Inwestuj w Turbo
Description
Certyfikaty strukturyzowane Turbo notowane na Giełdzie Papierów Wartościowych. Twoje centrum wiadomości.
Language
pl
Canonical
https://localhost:5000/

Open Graph

title
ING Turbo | Inwestuj w Turbo

Technology

Third-party hosts loaded (2)

  • cdn.ingmarkets.pl×6
  • localhost×1

Contact

Phone

DNS records live

NS
  • ns1-04.azure-dns.com
  • ns2-04.azure-dns.net
  • ns3-04.azure-dns.org
  • ns4-04.azure-dns.info
MX
  • 10 mr1.ing.pl
  • 20 mr2.ing.pl
TXT
Show 8 TXT records
  • swisssign-check=tCmXzzQhDKbd-93KMTDUXUAfapE
  • swisssign-check=0fgAQpAraSMqZeOGVm9wNajyCs8
  • identrust_validate=v6RQ11KVT82usvcsv5pSHx50y13DPFTW2AQc5890DDeb
  • 5d/hwMfk+VN28LFtWGfqJQkfqiSe6FVUXpTQXVxNjky8
  • identrust_validate=jv29GsOOQ4Toiopv+iUJd6CjDGESLcZ1TldYJfdXZrva
  • identrust_validate=IP+GW0y4YgrdHJlF7JTjdU8pUcqWdwE6sqw/Si0QL4EV
  • identrust_validate=6zFVj2FBVIscRp2FsOUBpRydDROTCmu6yqXs/VjUXbMy
  • identrust_validate=z1YHyTDve0tLeSCSYi7tneN0SZw5cE4pcRrKxjShsg+w
Verified for
  • Microsoft 365

Email authentication partial

SPF
v=spf1 mx a ip4:81.26.212.50 ip4:91.220.123.126 include:u969379.wl.sendgrid.net include:spf-include.mistermail.nl include:ing.pl -all
strict (-all)
DMARC
v=DMARC1; p=none; rua=mailto:info@ingturbo.pl,mailto:ejdvezzq@ag.eu.dmarcadvisor.com; fo=1; pct=100; aspf=r
policy: none (monitoring only)
DKIM
  • s1: k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAx1EF8LX69YM54AowohMn1PAqc8FWIS3G/wI2aTPzcqHT7q6MPn5yEHdzVpN5d2Zw+neZbv2mnfTE83taaP…
  • s2: k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCyeS9C+iGxfzE/zpuO11hRE/2AUyE3toovuOwjT3UYw8sf0yg0JrLna/5RvBgWNqCNRJ6SbW4mItWT2KztoraNzC…
selectors probed

Certificate (current)

HydrantID Server CA O1
from 2025-06-10 to 2026-07-05
Expires in 35 days

HTTP security headers

Header hygiene 90/100 Checked live page: https://www.ingturbo.pl/

present
  • strict-transport-security
  • content-security-policy
  • x-frame-options
  • x-content-type-options
  • referrer-policy
  • permissions-policy
  • cross-origin-opener-policy
  • cross-origin-resource-policy
findings
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
Header values
referrer-policy
no-referrer-when-downgrade
x-frame-options
SAMEORIGIN
permissions-policy
accelerometer=(), ambient-light-sensor=(), autoplay=(self), battery=(), camera=(), cross-origin-isolated=(), display-capture=(), document-domain=(), encrypted-media=(), execution-while-not-rendered=(), execution-while-out-of-viewport=(), fullscreen=(self), geolocation=(), gyroscope=(), keyboard-map=(), magnetometer=(), microphone=(), midi=(), navigation-override=(), payment=(), picture-in-picture=(self), publickey-credentials-get=(), screen-wake-lock=(), sync-xhr=(), usb=(), web-share=(), xr-spatial-tracking=()
x-content-type-options
nosniff
content-security-policy
base-uri 'self'; default-src 'self'; img-src 'self' https://api.ingmarkets.com https://cdn.ingmarkets.pl www.googletagmanager.com matomo.ing.cloudops.it *.visualwebsiteoptimizer.com app.vwo.com data: www.ingwb.com abmfn.com ingsprinters01.wt-eu02.net fbc.wcfbc.net; script-src 'self' 'unsafe-inline' 'unsafe-eval' www.googletagmanager.com responder.wt-safetag.com matomo.ing.cloudops.it www.youtube.com www.youtube-nocookie.com *.visualwebsiteoptimizer.com app.vwo.com https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/; style-src 'self' 'unsafe-inline'; connect-src ws: 'self' https://api.ingmarkets.com https://ingfm-quoteproxy.v-i.nl https://www.ingturbo.pl matomo.ing.cloudops.it *.visualwebsiteoptimizer.com app.vwo.com https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/; font-src 'self'; frame-ancestors 'self'; frame-src 'self' www.youtube.com www.youtube-nocookie.com *.visualwebsiteoptimizer.com app.vwo.com https://www.google.com/recaptcha/ https://www.g
strict-transport-security
max-age=31536000; includeSubDomains
cross-origin-opener-policy
same-origin
cross-origin-resource-policy
same-origin

Links to (2)

Linked from (1)