
Is dragon.cz Safe? Security Analysis for Dragon Internet a.s.
Check if dragon.cz is a scam or legitimate. Free security scan and reviews.
AI Summary
Dragon Internet a.s. is a well-established Czech internet service provider founded in 1997, offering a broad range of telecommunications services including high-speed internet via optical, microwave, and mobile networks, television services including Skylink, telephony, and technical support such as Apple device and PC servicing. The company targets both residential and business customers, positioning itself as a reliable and diversified ISP in the Czech market. The website reflects a professional and consistent brand image with clear navigation and relevant content tailored to its audience. Technically, the site employs modern tracking and marketing technologies such as Google Tag Manager, Facebook Pixel, and Targito, and integrates external services like Smartform.cz for form handling and Google Maps API for location services. The site is mobile optimized and accessible, with good SEO practices evident in meta tags and structured content. Security-wise, the site enforces HTTPS and uses secure forms with CSRF tokens, but lacks explicit security headers and a published security or incident response policy. Privacy compliance is strong, with a comprehensive privacy policy, cookie consent mechanism, and GDPR adherence. Overall, the site scores well on content quality, technical implementation, security posture, privacy compliance, and business credibility, reflecting a mature digital presence. Recommendations include enhancing security headers, publishing a security policy, and adding a vulnerability disclosure mechanism to further strengthen trust and security posture.
Detected Technologies
đź§ AI Business Intelligence
Technology stack, business insights, and market analysis powered by AI.
Business Intelligence
Market & Strategic Analysis
Dragon Internet a.s. operates in the telecommunications sector, focusing on internet and TV services with additional offerings such as telephony and device servicing. The company leverages a multi-channel business model combining direct service provision with e-commerce via its linked e-shop domain. Its market positioning is that of an established mid-sized ISP with a diversified portfolio catering to both households and businesses. The company maintains a strong partnership ecosystem, including remote support via TeamViewer and marketing via Targito. Growth indicators include recent news updates and service expansions. The company’s digital presence supports customer engagement through social media and a customer portal. Strategic observations suggest a focus on service quality, customer support, and digital marketing to maintain competitive advantage in the Czech market.
Extracted Contact Information
Marketing Intelligence Data
Physical Addresses (1)
Security Posture Analysis
Comprehensive Security Assessment
The website demonstrates a solid security foundation with HTTPS enforced and secure form handling including CSRF tokens. Cookie consent is managed in compliance with GDPR, and tracking scripts are loaded asynchronously to minimize performance impact. However, the absence of explicit security headers such as Content-Security-Policy, X-Frame-Options, and Strict-Transport-Security reduces the overall security posture. No incident response or security contact information is published, which could hinder timely vulnerability reporting and response. No vulnerability disclosure or security.txt file is present, limiting transparency. No exposed sensitive data or vulnerable libraries were detected in the HTML content. Overall, the security maturity is good but could be improved by adopting additional security best practices and publishing clear security policies.
Strategic Recommendations
Priority Actions for Security Improvement
Implement and enforce security headers including Content-Security-Policy, X-Frame-Options, and Strict-Transport-Security to enhance protection against common web attacks.
✨Observations
AI-powered comprehensive website and business analysis.
AI-Enhanced Website Analysis
Business Insights
Dragon Internet a.s.
Dragon Internet a.s. is a provider of internet services via optical, microwave, and mobile networks, offering internet, TV, Apple service, and PC service.
good
consistent
Technical Stack
moderate
good
good
good
Security Assessment
- HTTPS enforced
- Consent management for cookies
- No exposed sensitive data in HTML
- Secure contact form with CSRF token
Analytics & Tracking
Advertising & Marketing
Website Quality Assessment
Key Observations
Website is professionally designed and well-structured.
🛡️Security Headers
HTTP security headers analysis and recommendations.
Security Headers
HTTP security headers analysis
Weak Referrer-Policy configuration
LOWCurrent value: "same-origin"
Sensitive data may be cached
LOWCache-Control header should include "no-store" for sensitive pages
👤GDPR Compliance
Privacy and data protection assessment under GDPR regulations.
GDPR Compliance
Privacy and data protection assessment
No Privacy Policy found
HIGHGDPR requires a clear and accessible privacy policy
No Cookie Consent Banner found
HIGHGDPR requires explicit consent for non-essential cookies
EU business without adequate privacy measures
CRITICALEU businesses are subject to strict GDPR requirements
Third-party services without privacy policy
HIGHDetected services: Google Analytics, Facebook, LinkedIn, YouTube
GDPR Compliance Analysis
🛡️NIS2 Compliance
Network & Information Security Directive compliance assessment.
NIS2 Compliance
Network & Information Security Directive
No information security framework found
HIGHNIS2 requires documented cybersecurity and information security measures
No vulnerability disclosure policy
MEDIUMNIS2 encourages coordinated vulnerability disclosure
No security policy documentation found
HIGHNIS2 requires documented cybersecurity governance and risk management
No incident response procedures found
HIGHNIS2 requires documented incident response and business continuity plans
No business continuity planning found
MEDIUMNIS2 emphasizes operational resilience and business continuity
No security contact information
HIGHNIS2 requires clear incident reporting channels
No vulnerability reporting mechanism
MEDIUMClear vulnerability reporting supports coordinated disclosure
No NIS2 reference found
LOWConsider explicitly mentioning NIS2 compliance efforts
đź“§Email Security
SPF, DKIM, and DMARC validation and email security assessment.
Email Security
SPF, DKIM, and DMARC validation
DMARC not enforcing
MEDIUMDMARC policy is set to "none"
No DKIM record found
MEDIUMDKIM adds cryptographic signatures to emails
No BIMI Record
LOWBIMI displays brand logos in email clients
No MTA-STS Policy
MEDIUMMTA-STS enforces TLS for email delivery
No TLS-RPT Record
LOWTLS-RPT provides reporting for email TLS issues
SPF Details
DMARC Details
🏆SSL/TLS Security
Certificate validity and encryption analysis.
SSL/TLS Security
Certificate validity and encryption analysis
Mixed Content Detected
MEDIUM1 resources loaded over insecure HTTP
Partial SSL/TLS Assessment
LOWCompleted 2 of 4 security checks due to time constraints
Certificate Details
OCSP Status
📊DNS Health
DNS configuration and security assessment.
DNS Health
DNS configuration and security assessment
DNSSEC Not Enabled
MEDIUMDNSSEC is not configured for this domain
CAA Records Not Configured
LOWCertificate Authority Authorization (CAA) records not found
DMARC Policy Set to None
LOWDMARC is configured but not enforcing any policy
Domain Registration Details
DNS Records
DNSSEC Status
DNS Performance
SPF Analysis
⚡Network Security
Port scanning and network exposure analysis.
Network Security
Port scanning and network exposure analysis
Good Network Security Posture
LOWNo unnecessary services detected on common risky ports
đź”§Technical Analysis
Detailed technical findings and analysis from AI assessment.
Technical Analysis
Comprehensive security assessment findings