tzfpolfa.pl

.pl crawl

First seen 2026-05-24 · Last seen 2026-05-31 · ok HTTP/1.1 200 3553 ms crawled 2026-05-29

PL · 94.152.11.161 · AS29522 Cyber_Folks S.A.

Reputation 89/100 weak security headers dmarc monitor-only

sector health type homepage

HTML metadata

Title
Strona Główna - TZF Polfa
Description
Polfa Tarchomin - polski producent leków: antybiotyków, insulin, leków dermatologicznych i suplementów diety. Kochamy życie, podejmujemy wyzwania.
Language
pl-PL
Generator
WPML ver:4.9.4 stt:1,40;
Canonical
https://tzfpolfa.pl/

Open Graph

url
https://tzfpolfa.pl/
title
Strona Główna - TZF Polfa
locale
pl_PL
site name
TZF Polfa
description
Polfa Tarchomin - polski producent leków: antybiotyków, insulin, leków dermatologicznych i suplementów diety. Kochamy życie, podejmujemy wyzwania.

Technology

Server
nginx
CMS
WordPress

Third-party hosts loaded (1)

  • cdn-cookieyes.com×1

Social

Contact

Phone

DNS records live

NS
  • ns1.domeny.host
  • ns2.domeny.host
MX
  • 10 tzfpolfa.pl
Verified for
  • Google

Email authentication partial

SPF
v=spf1 a mx include:spf.tld.pl -all
strict (-all)
DMARC
v=DMARC1; p=none; sp=none
policy: none (monitoring only) · sp=none
DKIM
no key found at common selectors

Certificate (current)

R13
from 2026-04-09 to 2026-07-08
Expires in 37 days

HTTP security headers

Header hygiene 45/100 Checked live page: https://tzfpolfa.pl/

present
  • content-security-policy
findings
  • missing HSTS
  • CSP uses wildcard sources
  • missing frame protection
  • missing content type protection
  • missing Referrer Policy
  • missing Permissions Policy
Header values
content-security-policy
default-src 'self'; base-uri 'self'; object-src 'none'; form-action 'self'; frame-ancestors 'self'; upgrade-insecure-requests; script-src 'self' 'nonce-JH+Ec95T75lSA41ONeB4LQ=='; script-src-elem 'self' 'nonce-JH+Ec95T75lSA41ONeB4LQ==' https://www.googletagmanager.com https://tagmanager.google.com https://www.google-analytics.com https://ssl.google-analytics.com https://challenges.cloudflare.com https://cdn.cookieyes.com https://cdn-cookieyes.com https://*.cookieyes.com; script-src-attr 'none'; connect-src 'self' https://www.google-analytics.com https://stats.g.doubleclick.net https://region1.google-analytics.com https://tagmanager.google.com https://*.cookieyes.com https://cdn.cookieyes.com https://cdn-cookieyes.com https://challenges.cloudflare.com; img-src 'self' data: blob: https://www.google-analytics.com https://stats.g.doubleclick.net https://*.g.doubleclick.net https://*.cookieyes.com https://cdn.cookieyes.com https://cdn-cookieyes.com; frame-src https://challenges.cloudflare.co

Links to (3)

Linked from (2)