pasek-budownictwo.com.pl
HTML metadata
Technology
- Server
- LiteSpeed
- Fonts
-
- Google Fonts
Third-party hosts loaded (2)
- fonts.googleapis.com×1
- fonts.gstatic.com×1
Social
Contact
- Phone
DNS records live
- NS
-
- ns1.zenbox.pl
- ns2.zenbox.pl
- MX
-
- 10 mx1.zenbox.pl
- 20 mx2.zenbox.pl
- 30 mx3.zenbox.pl
- TXT
-
3f1ce4c948b9f5d31c9871f334dfb60894a26d4a8467636ffad65ba6510ed2f97f417d0f0b9358d16f639eb3c5548da4f9143f9abe105a5313d4701827ff88
Email authentication strong
- SPF
-
v=spf1 a mx include:_spf.zenbox.pl -allstrict (-all) - DMARC
-
v=DMARC1; p=reject; rua=mailto:pasek-budownictwo.com.plpolicy: reject (enforced) - DKIM
- no key found at common selectors
Certificate (current)
Certum DV TLS G2 R39 CA
Expires in 140 days
HTTP security headers
- present
-
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- missing HSTS
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Permissions Policy
Header values
- referrer-policy
strict-origin- x-frame-options
SameOrigin- x-content-type-options
nosniff- content-security-policy
default-src 'none'; script-src 'self' https://apis.google.com https://ajax.googleapis.com https://platform.twitter.com https://tagmanager.google.com https://www.googletagmanager.com https://www.google-analytics.com https://*.google-analytics.com https://www.googleadservices.com www.googleadservices.com https://www.google.com https://www.google.pl www.google.com www.google.pl https://www.gstatic.com https://googleads.g.doubleclick.net 'nonce-cTYuN/b7y9hQnIWLrQ/8Rg==' 'nonce-su6CEiL+ex7ItkG1kScWUw==' 'nonce-2zZosN8okkimeEPpwJ8Ayw=='; connect-src 'self' https://www.google-analytics.com https://*.google-analytics.com; img-src 'self' data: 'unsafe-inline' https://img.youtube.com https://i.ytimg.com https://vumbnail.com https://ssl.gstatic.com https://www.gstatic.com https://www.google-analytics.com https://googleads.g.doubleclick.net https://stats.g.doubleclick.net https://www.google.com https://www.google.pl www.google.com www.google.pl; media-src 'self'; style-src 'self' 'unsafe-inline' h