medicover.pl
HTML metadata
Technology
- Analytics
-
- Google Tag Manager
Third-party hosts loaded (1)
- www.googletagmanager.com×1
Social
Contact
- Phone
DNS records live
- NS
-
- dns1.cscdns.net
- dns2.cscdns.net
- MX
-
- 0 mx.emea.email.fireeyecloud.com
- TXT
-
Show 6 TXT records
onet-domain-verification=e50befbb9bbacf1209bbe930490329d6abe5794e5be2428f651300a523443025_udfgd5h246vc4f29erkbxdzym3q3ws6c4395d3b3c0ea6d5d83569291bd63a77have-i-been-pwned-verification=c0137fa6e933602c9206d66dbf6c181739yFE3MYpM4vKdrpmUCxaomPvGfITlRxkM6vvc4cBaSD1+LLgT6kOO4O5RXN0LVods0Tp1XlKhKdHJxJgM4Kug==QD7YOyMqCSXsO1IKZz82dfS44+VIIPetgOtfoQWl0vrLq5Iu9CVgLiMQKvl9VLICaxaB8Zw8jfFTk2jsj03ArQ==
- Verified for
-
- Apple
- Atlassian
- GlobalSign
- Google Workspace
Email authentication strong
- SPF
-
v=spf1 include:_spf.medicover.com include:spf.protection.outlook.com include:_spf.fireeyecloud.com -allstrict (-all) - DMARC
-
v=DMARC1;p=quarantine;pct=100;rua=mailto:dmarc_reports@medicover.com;ruf=mailto:dmarc_reports@medicover.com; aspf=s;adkim=s;fo=1policy: quarantine - DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQC+/lq15A8cR7J/3v7eu9oJmnuXAsh0Yryc5ZYPK3xXUTOr2bD6SkRkoxXQ+VP6Zglw9Ist3sO+Mkyldpp2wE…
selectors probed - selector1:
Certificate (current)
Corporation Service Company RSA OV SSL CA
Expires in 72 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- weak frame protection
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
ALLOW-FROM https://twitter.com- x-content-type-options
nosniff- content-security-policy
script-src 'self' 'unsafe-inline' 'unsafe-eval' https://unpkg.com *.medicover.pl https://www.strefaaptek.pl *.medistore.com.pl https://store.synevo.pl app3.salesmanago.pl sklep.rehasport.pl app3.salesmanago.com *.gstatic.com www.google.com *.googleapis.com *.google-analytics.com *.googletagmanager.com *.googleadservices.com googleads.g.doubleclick.net https://app3.emlgrid.com *.hotjar.com https://my.hellobar.com https://connect.facebook.net https://cdn.chatbot.com https://code.jquery.com https://cdnjs.cloudflare.com https://cdn-widget.callpage.io https://www.clarity.ms https://assets.pinterest.com/ https://promocja.medicover.pl/ https://cdn.livechatinc.com/ https://api.livechatinc.com/ *.consentmanager.net; frame-src 'self' https://www.strefaaptek.pl *.medistore.com.pl *.medicover.pl images.medicover.pl *.gdziepolek.pl covid19.infermedica.com https://koronawirusunas.pl/ platform.twitter.com *.google.com *.youtube.com youtu.be *.hotjar.com cdn.chatbot.com data: medistore.com.pl www.medi- strict-transport-security
max-age=31536000; includeSubDomains;