lh.pl
HTML metadata
Technology
- Server
- Apache
Third-party hosts loaded (1)
- www.google.com×1
Social
Contact
- Phone
- Address
- ul. ks. Jakuba Wujka 7/26, 61-581, Poznań, Polska
DNS records live
- NS
-
- ns.lh.pl
- ns2.lh.pl
- ns3.lh.pl
- MX
-
- 5 mail.lh.pl
- TXT
-
fb33beb2b260a9c4c47690eda636816a1dca84400f2d56f3db9138a17b6e444mojecertpl-site-verification-VLkNM9EQnBr4niZCAXX9s31UuV4gFVZuMS=4528D152D5BEE8E5F3EFBDD9BDBD5C2FFD1EDD57
- Verified for
-
- Microsoft 365
Email authentication strong
- SPF
-
v=spf1 include:_spf.lh.pl ip4:5.9.75.115/32 ip4:216.245.209.0/24 include:_spf.mailrelay.rrpproxy.net mx -allstrict (-all) - DMARC
-
v=DMARC1; p=reject; rua=mailto:dmarc-report@lh.pl;fo=1;policy: reject (enforced) - DKIM
-
- default:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAwWtqlIjSpu7EICXcEY+EbLIME4JfQvnOcML1KCq7sVyM52/jovnAbefT+tpyxPuDyhpybhsHVTj315…
selectors probed - default:
Certificate (current)
Certum DV TLS G2 R39 CA
Expires in 193 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
frame-ancestors 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://blueimp.github.io *.youtube.com *.jquery.com *.toast.com *.jsdelivr.net *.datatables.net *.cloudflare.com https://unpkg.com https://snap.licdn.com *.linkedin.com *.lh.pl *.googletagmanager.com *.facebook.net *.google-analytics.com *.doubleclick.net *.google.com *.gstatic.com www.googleadservices.com; object-src 'none'; style-src 'self' 'unsafe-inline' *.toast.com *.linkedin.com *.googleapis.com *.jsdelivr.net *.datatables.net *.cloudflare.com https://unpkg.com; img-src 'self' *.linkedin.com *.jsdelivr.net *.datatables.net *.cloudflare.com https://unpkg.com *.lh.pl *.ytimg.com *.googletagmanager.com *.facebook.net *.google-analytics.com *.doubleclick.net *.google.com *.gstatic.com www.googleadservices.com data: *.google.pl *.google.com *.google-analytics.com *.facebook.com; font-src 'self' *.gstatic.com;- strict-transport-security
max-age=63072000;