teraz-srodowisko.pl
HTML metadata
Technology
- Server
- Apache
- Analytics
-
- Google Tag Manager
Third-party hosts loaded (1)
- www.googletagmanager.com×1
Social
DNS records live
- NS
-
- a.dns.gandi.net
- b.dns.gandi.net
- c.dns.gandi.net
- MX
-
- 10 spool.mail.gandi.net
- 50 fb.mail.gandi.net
Email authentication strong
- SPF
-
v=spf1 a ip4:109.69.190.4 ip4:109.69.189.105 include:spf.tipimail.com include:_mailcust.gandi.net ~allsoftfail (~all) - DMARC
-
v=DMARC1;p=reject;rua=mailto:nasri@teraz-srodowisko.plpolicy: reject (enforced) - DKIM
-
- mail:
v=DKIM1;k=rsa;p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDa+hnKi49yx2vtOTd7kzUrzhsVVlsHzc+m6rkx5qLacruwy1vmirKG/ozBC7bcwnt+91ScziV2jUEL1KZzSwHb…
selectors probed - mail:
Certificate (current)
Sectigo RSA Domain Validation Secure Server CA
Expires in 21 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- weak frame protection
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
SAMEORIGIN, sameorigin- x-content-type-options
nosniff- content-security-policy
default-src https: 'unsafe-inline' 'unsafe-eval'; object-src 'none'; img-src https: data: 'self'; frame-ancestors 'self' http: https:; base-uri 'self'; form-action 'self' https://*.paybox.com- strict-transport-security
max-age=63072000; includeSubDomains; preload, max-age=15768000; preload