otodom.pl
HTML metadata
Technology
- CDN
- Amazon CloudFront
- CMS
- Next.js
- JS framework
- Next.js
- Cookie consent
-
- OneTrust
Third-party hosts loaded (8)
- cdn.cookielaw.org×2
- ireland.apollo.olxcdn.com×2
- laquesis.data.olxcdn.com×2
- tracking.olx-st.com×2
- cdn.slots.baxter.olx.org×1
- ninja.data.olxcdn.com×1
- www.imovirtual.com×1
- www.storia.ro×1
Social
Contact
- Address
- ul. Królowej Jadwigi 43, 61-872, Poznań, Poznań/Pojezierze Wielkopolskie, PL
DNS records live
- NS
-
- ns1.re.prd.verticals.olx.org
- ns2.re.prd.verticals.olx.org
- ns3.re.prd.verticals.olx.org
- ns4.re.prd.verticals.olx.org
- MX
-
- 20 aspmx.l.google.com
- 30 alt1.aspmx.l.google.com
- 30 alt2.aspmx.l.google.com
- 40 alt3.aspmx.l.google.com
- 40 alt4.aspmx.l.google.com
- TXT
-
Show 5 TXT records
983ca411e7286ff8a0f6667850f7f093lovable_verification=workspace_mgb27s7qf5eqewx9scdocker-verification=fc9d8fb7-8ff2-45a5-8916-449237e03047_rztorahct4ozqw5optt920s9slcmhbrstrike-domain-verification=12b78349-ea8e-4299-a203-67171fea6951
- Verified for
-
- Anthropic
- Atlassian
- Cursor
- Meta
- Microsoft 365
- OneTrust
- Workplace
- Yahoo
- Zoom
Email authentication strong
- SPF
-
v=spf1 include:anlev6r7p0.powerspf.com ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=reject; rua=mailto:k6zc3g74cn@rua.powerdmarc.com; ruf=mailto:k6zc3g74cn@ruf.powerdmarc.com; pct=100;policy: reject (enforced) - DKIM
-
- default:
v=DKIM1; g=*; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDADOPou9UCgKYXDYedPP1AfSXIQS+sMxEGG7YUPGNyxqV+GhkPGuZ5Zqet1i1SqS/4BDfLPaBbaqt4O… - google:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCWleLchRIoJEOJQPD+8Wqw+mq8tDLNxlXz/CM9cl0vAA+wvArPeFxYGlvs+rLR59W8m6DLPB72Av0IRv9mou… - smtpapi:
k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDPtW5iwpXVPiH5FzJ7Nrl8USzuY9zqqzjE0D1r04xDN6qwziDnmgcFNNfMewVKN2D1O+2J9N14hRprzByFwfQW76…
selectors probed - default:
Certificate (current)
Amazon RSA 2048 M04
Expires in 183 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- cross-origin-opener-policy
- cross-origin-embedder-policy
- cross-origin-resource-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Permissions Policy
Header values
- referrer-policy
no-referrer-when-downgrade- x-frame-options
DENY- x-content-type-options
nosniff- content-security-policy
default-src 'self' *.otodom.pl; connect-src 'self' https: wss://*.hotjar.com; font-src 'self' data: https:; frame-src 'self' https:; img-src 'self' https: blob: data:; manifest-src 'none'; media-src data: https://ireland.apollo.olxcdn.com; object-src 'none'; script-src 'self' https: 'unsafe-inline' 'unsafe-eval'; style-src 'self' https: 'unsafe-inline'; worker-src 'self' https://*.otodom.pl blob:; child-src 'self' https://*.otodom.pl blob:- strict-transport-security
max-age=63072000; includeSubDomains; preload- cross-origin-opener-policy
same-origin-allow-popups- cross-origin-embedder-policy
unsafe-none- cross-origin-resource-policy
cross-origin
Links to (16)
- apple.com×1
- facebook.com×1
- fixly.pl×1
- fliphtml5.com×1
- google.com×1
- imovirtual.com×1
- instagram.com×1
- linkedin.com×1
- obido.pl×1
- olx.pl×1
- olxgroup.com×1
- otomoto.pl×1
- spotify.com×1
- tiktok.com×1
- twitter.com×1
- youtube.com×1
Linked from (8)
- frn.pl×1
- pressummit.pl×1
- obido.pl×1
- olx.pl×1
- smmiechowice.bytom.pl×1
- fixly.pl×1
- imovirtual.com×1
- olxgroup.com×1