pekaobh.pl

.pl crawl

First seen 2026-05-28 · Last seen 2026-05-31 · ok HTTP/1.1 200 1085 ms crawled 2026-05-31

PL · 193.111.166.166 · AS24879 Bank Polska Kasa Opieki S.A.

Reputation 94/100 dmarc monitor-only

Classifying

HTML metadata

Title
Pekao Bank Hipoteczny
Language
pl

Technology

Analytics
  • Google Tag Manager

Third-party hosts loaded (1)

  • www.googletagmanager.com×1

Contact

Phone

DNS records live

NS
  • dns.pekao.com.pl
MX
  • 10 mailgate.pekaobh.pl
TXT
  • MS=BA3D2DE3D492F7814143BB492FBAF44E20E006CC
  • 6cff4d21e62dcfde314c1e3224c5cf93be048486240e6677575975d7c103a060
Verified for
  • Apple

Email authentication partial

SPF
v=spf1 ip4:193.111.166.239 ip4:193.111.166.240 ip4:193.111.166.241 -all
strict (-all)
DMARC
v=DMARC1;p=none;rua=mailto:dmarc.info@pekao.com.pl!5m;pct=10;adkim=r;aspf=r;ri=86400
policy: none (monitoring only) · pct=10
DKIM
no key found at common selectors

Certificate (current)

Certum Extended Validation CA SHA2
from 2025-06-10 to 2026-06-10
Expires in 10 days

HTTP security headers

Header hygiene 85/100 Checked live page: https://www.pekaobh.pl/

present
  • strict-transport-security
  • content-security-policy
  • x-frame-options
  • x-content-type-options
  • referrer-policy
findings
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
  • missing Permissions Policy
Header values
referrer-policy
origin-when-cross-origin
x-frame-options
sameorigin
x-content-type-options
nosniff
content-security-policy
script-src 'self' https://*.googletagmanager.com https://*.gstatic.com https://*.google.com https://*.google.pl https://*.google-analytics.com https://*.googleapis.com https://*.googleadservices.com https://*.ggpht.com https://*.googleusercontent.com https://googleads.g.doubleclick.net https://connect.facebook.net https://www.snrcdn.net https://chat.pekao.com.pl https://public.tableau.com https://bat.bing.com https://platform.twitter.com 'unsafe-inline' 'unsafe-eval' blob:; frame-ancestors 'self'; object-src 'none';
strict-transport-security
max-age=31536000; includeSubdomains; preload

Links to (2)

Linked from (1)