xzone.cz
HTML metadata
Technology
- Server
- Apache
- jQuery
- 3.6.0
- Stack
- PHP
- Analytics
-
- Google Tag Manager
Third-party hosts loaded (6)
- www.googletagmanager.com×1
- www.xzone.at×1
- www.xzone.de×1
- www.xzone.hu×1
- www.xzone.pl×1
- www.xzone.sk×1
Social
Contact
DNS records
Email authentication partial
- SPF
-
v=spf1 a:xzone.cz mx ip4:62.109.134.6 ip6:2001:1ab0:7e1e:d150:5054:ff:fea9:6ac0 include:_emailing.heureka.cz include:_spf.ignum.cz include:spf.smartemailing.cz include:spf1.supportbox.cz -allstrict (-all) - DMARC
-
v=DMARC1; p=none; rua=mailto:dmarc+4743@smartemailing.cz; ruf=mailto:hanus_problem@xzone.cz; fo=1policy: none (monitoring only) - DKIM
-
- default:
v=DKIM1; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAz5D/TEEKourB30ubwj29f4zvhAspUl+hXd2ACSm4UtLeR+JhF1mlgK6c0gGbkDNWojJ6yJHawV/1DlJ0…
selectors probed - default:
Certificate (current)
R13
Expires in 78 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
deny- x-content-type-options
nosniff- content-security-policy
script-src 'strict-dynamic' 'nonce-00d57bd1e931d184c8407b1f5ee4f7f7' 'unsafe-eval' 'unsafe-inline' http: https: s.kk-resources.com web-sdk.smartlook.com www.googleadservices.com im9.cz supportbox.cz *.seznam.cz *.zbozi.cz *.xzone.cz *.klarna.com xzone.test;img-src 'self' api.paylibo.com placehold.co xzone.cz csfd.cz *.seznam.cz *.zbozi.cz *.idealo.com *.kingdomcome-store.com blob: data: tracking.smartemailing.cz *.twisto.cz i.ibb.co *.xzone.cz *.xzone.sk *.xzone.hu *.xzone.de *.xzone.at *.gamlery.pl *.xzone.pl *.ceneo.pl *.gamlery.cz *.csfd.cz *.google-analytics.com *.google.com *.google.cz *.google.sk *.google.hu *.google.pl *.google.de *.google.at *.google.co.uk googleads.g.doubleclick.net *.googletagmanager.com *.googleadservices.com stats.g.doubleclick.net www.facebook.com connect.facebook.net cdnjs.cloudflare.com steamcdn-a.akamaihd.net static.muve.cz ssl.heureka.cz *.heureka.cz *.heureka.sk *.estores.cz *.filmexpres.cz *.dvdexpres.sk *.gameexpress.hu *.seznam.cz *.cdninstagram.c- strict-transport-security
max-age=63072000; includeSubDomains; preload
Links to (5)
- facebook.com×1
- instagram.com×1
- shoproku.cz×1
- x.com×1
- youtube.com×1