mfinanse.pl
HTML metadata
Technology
- Server
- mfinanse
- CMS
- WordPress
- Analytics
-
- Google Tag Manager
Third-party hosts loaded (3)
- www.facebook.com×2
- challenges.cloudflare.com×1
- www.googletagmanager.com×1
Social
Contact
- Phone
DNS records live
- NS
-
- buck.ns.cloudflare.com
- nadia.ns.cloudflare.com
- MX
-
- 10 mx00.mfinanse.pl
- 20 mx01.mfinanse.pl
- TXT
-
MS=D5A87B954EE61B62D45E8AB3F0B42DDFCDD3A286
- Verified for
-
- Apple
- Cisco
- Microsoft 365
- Zoom
Email authentication strong
- SPF
-
v=spf1 ip4:217.153.98.112 ip4:217.153.98.68 ip4:217.153.98.69 ip4:217.153.98.70 ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=quarantine; rua=mailto:19f9b563045c49eb96dfca3028b50eba@dmarc-reports.cloudflare.netpolicy: quarantine - DKIM
-
- mail:
v=DKIM1; h=sha256; k=rsa; p=MIICIjANBgkqhkiG9w0BAQEFAAOCAg8AMIICCgKCAgEAqhnoKMt09pvXqnhxhUbkX2+yb3Oii5siXCQdMxUK8culGOjh2fIUu+xrKepVRZ4Yjdsa…
selectors probed - mail:
Certificate (current)
Certum Domain Validation CA SHA2
Expires in 4 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Permissions Policy
Header values
- referrer-policy
no-referrer- x-frame-options
sameorigin- x-content-type-options
nosniff- content-security-policy
frame-ancestors https://www.google.com https://mfinanse.pl https://vars.hotjar.com ; block-all-mixed-content; default-src 'none'; script-src 'self' 'report-sample' 'unsafe-inline' 'unsafe-eval' https://challenges.cloudflare.com/turnstile/ https://consentcdn.cookiebot.com/consentconfig/ https://consent.cookiebot.com/Scripts/widget.min.js https://consent.cookiebot.com/Scripts/widgetIcon.min.js https://consent.cookiebot.com/logconsent.ashx https://consent.cookiebot.com/111f5663-b98b-4eec-86b7-a60d1f578d53/cc.js https://consentcdn.cookiebot.com/consentconfig/111f5663-b98b-4eec-86b7-a60d1f578d53/state.js https://consent.cookiebot.com/uc.js https://kalkulator-hipoteczny.online/js/app.js https://*.doubleclick.net https://*.google.com https://*.googleadservices.com https://*.googlesyndication.com https://*.googletagservices.com https://connect.facebook.net https://googleads.g.doubleclick.net https://graph.facebook.com https://google-analytics.com https://googletagmanager.com https://js.facebo- strict-transport-security
max-age=63072000; includeSubDomains; preload
Links to (6)
- zpf.pl×1
- youtube.com×1
- mbank.pl×1
- linkedin.com×1
- facebook.com×1
- cloudflare.com×1