z500.sk
HTML metadata
Technology
- Server
- Apache
- Stack
- PHP
- Analytics
-
- Google Tag Manager
- Fonts
-
- Google Fonts
Third-party hosts loaded (8)
- dfy26slkuyq65.cloudfront.net×26
- assets.z500.pl×4
- fonts.googleapis.com×2
- www.googletagmanager.com×2
- apis.google.com×1
- d3w4qvld0y469z.cloudfront.net×1
- facebook.com×1
- fonts.gstatic.com×1
Social
DNS records live
- NS
-
- ns1.z500.pl
- ns2.z500.pl
- MX
-
- 100 mailin2.z500.sk
- TXT
-
ac9aaca10bedbcc51e24588d7fc109d2a48b992150c22a5386cffb4d131c322spf2.0/pra a mx include:_sid.websupport.sk ?all
Email authentication partial
- SPF
-
v=spf1 a mx include:_spf.websupport.sk ?allneutral (?all) - DMARC
-
v=DMARC1; p=none;policy: none (monitoring only) - DKIM
- no key found at common selectors
Certificate (current)
R13
Expires in 36 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
sameorigin- x-content-type-options
nosniff- content-security-policy
default-src * 'unsafe-inline' 'unsafe-eval' data: blob:; script-src * 'unsafe-inline' 'unsafe-eval' data: blob:; style-src * 'unsafe-inline' data: blob:; img-src * 'unsafe-inline' data: blob:; connect-src * ws://* wss://*;- strict-transport-security
max-age=15768000, max-age=63072000; preload
z500.sk