nandana.cz

.cz crawl

First seen 2026-06-01 · Last seen 2026-06-01 · ok HTTP/1.1 200 997 ms crawled 2026-06-01

FR · 38.242.223.149 · AS51167 Contabo GmbH

Reputation 92/100 no dmarc policy

Classifying

HTML metadata

Title
Domů - Nandana — centrum pohybové medicíny
Description
Nandana — centrum pohybové medicíny
Language
cs

Technology

Server
Apache
jQuery
3.6.0
Stack
PHP
Analytics
  • Google Tag Manager

Third-party hosts loaded (1)

  • www.googletagmanager.com×1

Social

Contact

Email
Phone

DNS records live

NS
  • ns.wedos.com
  • ns.wedos.cz
  • ns.wedos.eu
  • ns.wedos.net
MX
  • 1 wes1-mx1.wedos.net
  • 1 wes1-mx2.wedos.net
  • 10 wes1-mx-backup.wedos.net

Email authentication weak

SPF
v=spf1 a mx include:spf.pavelbyma.cz ~all
softfail (~all)
DMARC
not published
DKIM
  • default: v=DKIM1; k=rsa; s=email; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCdTtEqM8FqndiFYOderzljMMMqBdEp+wJKP+VUbhc9GigmK34ZjrSqqdKjIEWr2q9DvSVp1H1bZ…
selectors probed

Certificate (current)

R13
from 2026-05-09 to 2026-08-07
Expires in 66 days

HTTP security headers

Header hygiene 95/100 Checked live page: https://www.nandana.cz/

present
  • strict-transport-security
  • content-security-policy
  • x-frame-options
  • x-content-type-options
  • referrer-policy
  • permissions-policy
  • cross-origin-opener-policy
findings
  • CSP allows unsafe inline scripts/styles
Header values
referrer-policy
strict-origin-when-cross-origin
x-frame-options
SAMEORIGIN
permissions-policy
accelerometer=(),autoplay=(),camera=(),display-capture=(),document-domain=(),encrypted-media=(),fullscreen=(),geolocation=(),gyroscope=(),magnetometer=(),microphone=(),midi=(),payment=(),picture-in-picture=(),publickey-credentials-get=(),screen-wake-lock=(),sync-xhr=(self),usb=(),web-share=(),xr-spatial-tracking=()
x-content-type-options
nosniff
content-security-policy
default-src 'none'; img-src 'self' https: data:; connect-src 'self' https:; script-src 'nonce-W1ZTR87ZwYKd2UtgqWyW4N9K2Jc=' 'strict-dynamic' https: http:; style-src 'self' 'unsafe-inline' https:; media-src 'self'; font-src 'self' data: https:; form-action 'self'; base-uri 'none'; object-src 'none'; frame-src www.google.com; frame-ancestors 'none'
strict-transport-security
max-age=63072000; includeSubDomains; preload
cross-origin-opener-policy
same-origin

Links to (4)

Linked from (1)