zonky.cz
HTML metadata
Technology
- Server
- -
- CMS
- Next.js
- JS framework
- Next.js
- Cookie consent
-
- OneTrust
Third-party hosts loaded (2)
- cdn.siteone.io×52
- cdn.cookielaw.org×1
Social
DNS records live
- NS
-
- ns-1444.awsdns-52.org
- ns-1648.awsdns-14.co.uk
- ns-719.awsdns-25.net
- ns-72.awsdns-09.com
- MX
-
- 10 mx1.airbank.cz
- 20 mx2.airbank.cz
- 30 mx3.airbank.cz
- Verified for
-
- Atlassian
- Microsoft 365
Email authentication partial
- SPF
-
v=spf1 include:_spf.google.com include:spf.mandrillapp.com include:servers.mcsv.net include:mail.zendesk.com include:_spf.salesforce.com ip4:80.188.97.68 ip4:80.188.97.69 ip4:90.181.164.157 ip4:193.165.169.163 ip4:193.165.201.44 ip4:193.165.201.45 ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=none; sp=none; adkim=s; aspf=s; rua=mailto:dmarc@zonky.cz; ri=1209600; ruf=mailto:dmarc@zonky.cz; fo=0; rf=afrf; pct=100policy: none (monitoring only) · sp=none - DKIM
-
- google:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCBe/jr0U/QHYMFcfFC0oYL574ymbKApEA45V7Stt7JTkvK0lCGF/ofoMSwe/wVU1aB0AwL9RGHC3pM3ruCcX… - k1:
k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDbNrX2cY/GUKIFx2G/1I00ftdAj713WP9AQ1xir85i89sA2guU0ta4UX1Xzm06XIU6iBP41VwmPwBGRNofhBVR+e6WHUo…
selectors probed - google:
Certificate (current)
Thawte TLS ECC CA G1
Expires in 135 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
no-referrer-when-downgrade- x-frame-options
SAMEORIGIN- permissions-policy
accelerometer=(), camera=(), geolocation=(self), gyroscope=(), magnetometer=(), microphone=(), midi=(), payment=(), usb=()- x-content-type-options
nosniff- content-security-policy
default-src 'self' https://cdn.siteone.io 'unsafe-inline'; script-src 'unsafe-inline' 'unsafe-eval' 'self' https://zonky.my.site.com https://b.bing.com https://*.clarity.ms https://static.hotjar.com https://script.hotjar.com https://script.crazyegg.com https://s3.scriptcdn.net/ https://partner.zonky.cz https://cdn.siteone.io https://c.seznam.cz/js/rc.js https://cdn.cookielaw.org/scripttemplates/ https://connect.facebook.net https://b.static.lightning.force.com https://*.salesforceliveagent.com https://*.la1-c1-par.salesforceliveagent.com https://*.g.doubleclick.net https://login.dognet.sk https://polyfill.io https://service.force.com https://static.lightning.force.com https://zonky.force.com https://www.google-analytics.com https://ssl.google-analytics.com https://www.google.com https://*.googletagmanager.com https://www.youtube.com https://zonky.my.salesforce.com https://zonky--stage.sandbox.my.salesforce.com https://zonky.my.site.com https://tpc.googlesyndication.com https://www.go- strict-transport-security
max-age=15552000; includeSubDomains; preload