xzone.at
HTML metadata
Technology
- Server
- Apache
- jQuery
- 3.6.0
- Stack
- PHP
- Analytics
-
- Google Tag Manager
Third-party hosts loaded (6)
- www.googletagmanager.com×1
- www.xzone.cz×1
- www.xzone.de×1
- www.xzone.hu×1
- www.xzone.pl×1
- www.xzone.sk×1
Social
Contact
DNS records live
- NS
-
- ns1.webglobe.cz
- ns2.webglobe.cz
- ns3.webglobe.com
- MX
-
- 1 schovanec5-vm1.cust.ignum.cz
- Verified for
-
Email authentication strong
- SPF
-
v=spf1 a:xzone.at mx ip4:62.109.134.6 ip6:2001:1ab0:7e1e:d150:5054:ff:fea9:6ac0 include:_spf.ignum.cz include:spf.smartemailing.cz include:spf1.supportbox.cz -allstrict (-all) - DMARC
-
v=DMARC1; p=reject; rua=mailto:dmarc+4743@smartemailing.cz; ruf=mailto:hanus_problem@xzone.cz; fo=1policy: reject (enforced) - DKIM
-
- default:
v=DKIM1; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAz5D/TEEKourB30ubwj29f4zvhAspUl+hXd2ACSm4UtLeR+JhF1mlgK6c0gGbkDNWojJ6yJHawV/1DlJ0…
selectors probed - default:
Certificate (current)
R13
Expires in 75 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
deny- x-content-type-options
nosniff- content-security-policy
script-src 'strict-dynamic' 'nonce-3b661dc263e8465817998064219e1d8f' 'unsafe-eval' 'unsafe-inline' http: https: s.kk-resources.com web-sdk.smartlook.com www.googleadservices.com im9.cz supportbox.cz *.seznam.cz *.zbozi.cz *.xzone.cz *.klarna.com xzone.test;img-src 'self' api.paylibo.com placehold.co xzone.cz csfd.cz *.seznam.cz *.zbozi.cz *.idealo.com *.kingdomcome-store.com blob: data: tracking.smartemailing.cz *.twisto.cz i.ibb.co *.xzone.cz *.xzone.sk *.xzone.hu *.xzone.de *.xzone.at *.gamlery.pl *.xzone.pl *.ceneo.pl *.gamlery.cz *.csfd.cz *.google-analytics.com *.google.com *.google.cz *.google.sk *.google.hu *.google.pl *.google.de *.google.at *.google.co.uk googleads.g.doubleclick.net *.googletagmanager.com *.googleadservices.com stats.g.doubleclick.net www.facebook.com connect.facebook.net cdnjs.cloudflare.com steamcdn-a.akamaihd.net static.muve.cz ssl.heureka.cz *.heureka.cz *.heureka.sk *.estores.cz *.filmexpres.cz *.dvdexpres.sk *.gameexpress.hu *.seznam.cz *.cdninstagram.c- strict-transport-security
max-age=63072000; includeSubDomains; preload
Links to (6)
- xzone.pl×1
- xzone.de×1
- xzone.cz×1
- instagram.com×1
- geizhals.at×1
- facebook.com×1