ufg.pl
HTML metadata
Technology
- Server
- Microsoft-IIS
- ASP.NET
- 2.0.50727 end of life
DNS records live
- NS
-
- dns1.ufg.pl
- dns2.ufg.pl
- MX
-
- 10 mail1.ufg.pl
- 20 mail2.ufg.pl
- TXT
-
EC=EHLN8P2TVS5RBVRYHUPX9MS=F5FB331730CCA94F12807CB44256A4455A26361F
Email authentication strong
- SPF
-
v=spf1 ip4:193.25.184.0/23 a mx -allstrict (-all) - DMARC
-
v=DMARC1;p=quarantine;rua=mailto:dmarc_rua@ufg.pl;ruf=mailto:dmarc_ruf@ufg.pl;fo=1policy: quarantine - DKIM
-
- default:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEApb9j5t0VT0Sh9m0/5HC0dmB1W9Sb8g38Zsq+s+Eb0c2FxFTlLW3FbfO8bSOI5Jp1aLGEzoGJZB4unN…
selectors probed - default:
Certificate (current)
Certum Domain Validation CA SHA2
Expires in 89 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-content-type-options
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing frame protection
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-content-type-options
nosniff- content-security-policy
default-src https: *.ufg.pl; script-src https: *.ufg.pl 'unsafe-inline' 'unsafe-eval';style-src https: *.ufg.pl 'unsafe-inline';img-src 'self' data: https: www.google-analytics.com; frame-src https: *.ufg.pl; media-src data: https: *.ufg.pl; child-src https: *.ufg.pl blob:; worker-src blob:; frame-ancestors 'self' *.ufg.pl;- strict-transport-security
max-age=15768000