instaluj.cz
HTML metadata
Technology
- Server
- nginx
- jQuery
- 1.7.1 known XSS (<3.5)
- Analytics
-
- Google Tag Manager
- Ads
-
- Google AdSense
Third-party hosts loaded (7)
- pagead2.googlesyndication.com×4
- toplist.cz×2
- fundingchoicesmessages.google.com×1
- psmedia.cz×1
- www.facebook.com×1
- www.google.com×1
- www.googletagmanager.com×1
DNS records live
- NS
-
- ns.forpsi.cz
- ns.forpsi.it
- ns.forpsi.net
- MX
-
- 20 psmedia.vshosting.cz
- 40 mta.vshosting.cloud
- 50 mta.vshosting.eu
- 60 instaluj.vshosting.cz
- Verified for
-
Email authentication strong
- SPF
-
v=spf1 a mx ip4:185.59.208.192 ip4:78.24.9.9 include:_spf.vshosting.cloud include:_spf.google.com ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=quarantine; fo=1; adkim=s; aspf=s; pct=100; rf=afrf; ri=86400; sp=quarantine; rua=mailto:dmarc-rua@psmedia.cz;policy: quarantine · sp=quarantine - DKIM
-
- dkim:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCHa60nanPpOsJdKIcB7MEGShfnxZlhmVYarTT+nVk3TBhVH8o7QB8TBoyGHg7Hs8l2ndKUFbCoMHG2pX8EKB…
selectors probed - dkim:
Certificate (current)
YR2
Expires in 87 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-content-type-options
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing frame protection
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-content-type-options
nosniff- content-security-policy
default-src 'self'; frame-src 'self' instaluj.cz soubory.instaluj.cz ep2.adtrafficquality.google googleads.g.doubleclick.net *.google.com *.youtube.com *.facebook.com fundingchoicesmessages.google.com pagead2.googlesyndication.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' ep2.adtrafficquality.google *.google.com *.googletagmanager.com *.facebook.com *.googlesyndication.com *.gstatic.com psmedia.cz; style-src 'self' 'unsafe-inline' fonts.googleapis.com; img-src 'self' data: ad.doubleclick.net i.ytimg.com ep2.adtrafficquality.google ep1.adtrafficquality.google *.google.com *.googleusercontent.com *.googlesyndication.com *.googletagmanager.com *.facebook.com *.toplist.cz toplist.cz *.google.cz; font-src 'self' fonts.gstatic.com; connect-src 'self' ad.doubleclick.net csi.gstatic.com pagead2.googlesyndication.com ep1.adtrafficquality.google stats.g.doubleclick.net *.google-analytics.com *.googletagmanager.com *.facebook.com *.toplist.cz analytics.google.com region1.analytics.google.c- strict-transport-security
max-age=31536000; includeSubDomains; preload