nfsec.pl
HTML metadata
Technology
- Server
- httpd
- CMS
- WordPress
Third-party hosts loaded (1)
- gmpg.org×1
Social
DNS records live
- NS
-
- ns1.nfsec.pl
- ns2.nfsec.pl
- ns3.nfsec.pl
- ns4.nfsec.pl
- MX
-
- 1 aspmx.l.google.com
- 10 alt3.aspmx.l.google.com
- 10 alt4.aspmx.l.google.com
- 5 alt1.aspmx.l.google.com
- 5 alt2.aspmx.l.google.com
- Verified for
-
Email authentication strong
- SPF
-
v=spf1 a mx include:_spf.google.com -allstrict (-all) - DMARC
-
v=DMARC1; p=reject; sp=none; fo=1; pct=100; rua=mailto:cert@nfsec.pl; ruf=mailto:cert@nfsec.pl; adkim=s; aspf=s;policy: reject (enforced) · sp=none - DKIM
- no key found at common selectors
Certificate (current)
cyber_Folks
Expires in 269 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- cross-origin-opener-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
no-referrer- x-frame-options
SAMEORIGIN- permissions-policy
geolocation=(), camera=(), microphone=()- x-content-type-options
nosniff- content-security-policy
default-src 'self'; img-src 'self' *.gravatar.com data: ; script-src 'self' 'unsafe-inline'; style-src 'self' 'unsafe-inline'; font-src 'self' data: ; object-src 'self'; worker-src 'self'; media-src 'self'; frame-ancestors 'self'; base-uri 'self'; form-action 'self'; connect-src 'self'; upgrade-insecure-requests- strict-transport-security
max-age=31536000; includeSubDomains; preload- cross-origin-opener-policy
same-origin
Links to (25)
- xint.io×1
- wiz.io×1
- wikipedia.org×1
- w3schools.com×1
- ubuntu.com×1
- twitter.com×1
- timesys.com×1
- thomas-krenn.com×1
- righteousit.com×1
- redhat.com×1
- php.net×1
- mysql.com×1
- mitre.org×1
- manpagez.com×1
- man7.org×1
- lwn.net×1
- livesys.se×1
- kernel.org×1
- github.com×1
- follow.it×1
- devilteam.pl×1
- centos.com.pl×1
- bothunters.pl×1
- apache.org×1
- anarc.at×1