vinci-facilities.pl

.pl crawl

First seen 2026-05-27 · Last seen 2026-05-30 · ok HTTP/1.1 200 1987 ms crawled 2026-05-30

NL · 20.71.80.38 · AS8075 Microsoft Corporation

Reputation 100/100

Classifying

HTML metadata

Title
VINCI Facilities Polska - VINCI Facilities Polska
Language
en-GB
Canonical
https://www.vinci-facilities.pl/en/home/
Translations
  • en
  • pl

Open Graph

url
https://www.vinci-facilities.pl/en/home/
title
VINCI Facilities Polska
locale
en_GB
site name
VINCI Facilities Polska
locale:alternate
pl_PL

Technology

jQuery
3.7.1
Stack
PHP

DNS records live

NS
  • ns0.infravesi.com
  • ns1.infravesi.com
  • nsa.perf1.fr
  • nsb.perf1.com
  • nsc.perf1.com
MX
  • 5 vincifacilities-pl01c.mail.protection.outlook.com
TXT
  • jExlGMkqnr7T/qKzvkKb5Zja9LO9OxwVsnq7C6N/Y3u7bNZeQTojnqaSpGHQ7Kn4u888O0hUhUFGl2uF39/+tQ==
  • l%ZuOIe6hyq9Dj^LdO3jWN5zkNY6W6^IyZ4UW@@R#zwgKEunp2pgC5V7K*YM88h4v7Z^A9oKOAyj^C6i0Tccj6FHaW^9ME!NYau
  • v=msv1 t=8687297C-5278-46BF-A690-BFC8B5F8629A
Verified for
  • Google
  • Microsoft 365

Email authentication strong

SPF
v=spf1 include:spf.protection.outlook.com include:spf.protection.vinci-energies.com -all
strict (-all)
DMARC
v=DMARC1; p=reject; rua=mailto:dmarc@vinci-energies.com; pct=100; sp=reject
policy: reject (enforced) · sp=reject
DKIM
  • selector1: v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAw/lXgiWftHNv5H8J7RJkku0qr4ZujwDVFlqUAQZpM6oQUuxRg9nSMqhx0NCQKMHDnt9xaOEiKdE5RW…
selectors probed

Certificate (current)

R13
from 2026-03-30 to 2026-06-28
Expires in 27 days

HTTP security headers

Header hygiene 90/100 Checked live page: https://www.vinci-facilities.pl/en/home/

present
  • strict-transport-security
  • content-security-policy
  • x-frame-options
  • x-content-type-options
  • referrer-policy
findings
  • CSP allows unsafe inline scripts/styles
  • missing Permissions Policy
Header values
referrer-policy
no-referrer-when-downgrade
x-frame-options
SAMEORIGIN
x-content-type-options
nosniff
content-security-policy
default-src https:; font-src 'unsafe-inline' https: data:; child-src https: blob:; connect-src https: blob:; worker-src https: blob:; script-src 'unsafe-eval' 'unsafe-inline' 'self' https:; object-src; base-uri 'none'; style-src 'unsafe-inline' https: data:; img-src https: data:;
strict-transport-security
max-age=15552001; includeSubDomains;

Links to (1)

Linked from (2)