rodenstock.cz
HTML metadata
Technology
- Server
- Apache
- Stack
- Java
Third-party hosts loaded (19)
- www.rodenstock.be×2
- www.rodenstock.ch×2
- www.rodenstock.com×2
- cloud.ccm19.de×1
- www.rodenstock.at×1
- www.rodenstock.cl×1
- www.rodenstock.co.uk×1
- www.rodenstock.com.br×1
- www.rodenstock.com.uy×1
- www.rodenstock.de×1
- www.rodenstock.dk×1
- www.rodenstock.es×1
- www.rodenstock.fr×1
- www.rodenstock.it×1
- www.rodenstock.nl×1
- www.rodenstock.no×1
- www.rodenstock.pl×1
- www.rodenstock.si×1
- www.rodenstock.sk×1
Social
DNS records live
- NS
-
- ns1.ignum.com
- ns2.ignum.cz
- MX
-
- 10 mail.rodenstock.cz
- TXT
-
cmqqge1g3Kl37GWCyadkV6piPj8bqRVo
- Verified for
-
- Atlassian
- Microsoft 365
- OneTrust
Email authentication weak
- SPF
-
v=spf1 ip4:31.30.5.116 a:mailsn.rodenstock.com ip4:195.30.104.33 ip4:195.30.95.160/27 ip4:194.97.128.16/28 ip4:195.30.138.16/29 include:spf.protection.outlook.com ~allsoftfail (~all) - DMARC
- not published
- DKIM
- no key found at common selectors
Certificate (current)
Sectigo Public Server Authentication CA DV R36
Expires in 282 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-content-type-options
- findings
-
- CSP allows unsafe inline scripts/styles
- missing frame protection
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-content-type-options
nosniff- content-security-policy
frame-ancestors 'self'; worker-src 'self' blob:; script-src 'unsafe-inline' 'unsafe-eval' 'self' https://cloud.ccm19.de https://www.googletagmanager.com https://connect.facebook.net https://googleads.g.doubleclick.net https://maps.googleapis.com;- strict-transport-security
max-age=31536000; includeSubDomains