20 Headers

Detected Technologies from Headers

HTTP Security Headers

Status
Strict-Transport-Security
Excellent
max-age=31536000; includeSubDomains; preload
Content-Security-Policy
Good
default-src; connect-src; font-src; +6 more Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Excellent
DENY
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Present
origin
Permissions-Policy
Missing
Not configured
Recommendations
  • Strengthen CSP by removing 'unsafe-eval'
  • Consider adding Permissions-Policy to control browser features

Performance Headers

Connection
Performance
close
Transfer-Encoding
Performance
chunked
Vary
Performance
accept-encoding

Caching Headers

Cache-Control
Caching
no-store

Content Headers

Content-Language
Content
en-US-x-lvariant-USA
Content-Type
Content
text/html;charset=UTF-8

Server Headers

Server
Server
Apple

CORS Headers

No CORS headers found

Cookies Headers

Set-Cookie
Cookies

Other Headers

Date
Other
Fri, 03 Apr 2026 03:24:35 GMT
Host
Other
account.apple.com
Scnt
Other
AAAA-kIxOURFOUVDNTZDQjc3OEM2MzU0QUUzMzRFRjIyNDJFQTE4QUREQkE4RTFFNjFFOTFEREVENDU1NTAxRUJEMURCRUZGMjUyRTRGMUM3Q0UyMURFNzYwRDgwNkE5RjE1MjAxNUE4Qzc2ODk2Mjc3MkZBNDZGNkJERDg4NTVFOTkzMTA0MkZGQ0M0RDJENjA1NTgyQ0Q1QTg0RTA4RDIyRDhDRjlEODkwMTU5Rjk5OEI1NDhBODgwQTcwQUUyQTJGQzQ2RTRGM0FGQUJFRjlCMjU2RTkwRjQ0QkExMUQzODNCRDkxNDY1NzNGNUI1RDNDRHwxAAABnVFs6blSv7-9A0nNJvK47IMmZif1RRMBJOoWKfiuOYSQi97N1SMKe_0Gr49yAA2fyFQWJSrBu4_H5zeXyTGmXX3dKVEVLQAaNXmXX91jl2TYXCUKBw
X-Apple-I-Request-Id
Other
a383e932-2f0c-11f1-8eec-c1fb1145f638
X-Apple-Id-Session-Id
Other
B19DE9EC56CB778C6354AE334EF2242EA18ADDBA8E1E61E91DDED455501EBD1DBEFF252E4F1C7CE21DE760D806A9F152015A8C768962772FA46F6BDD8855E9931042FFCC4D2D605582CD5A84E08D22D8CF9D890159F998B548A880A70AE2A2FC46E4F3AFABEF9B256E90F44BA11D383BD9146573F5B5D3CD
X-Buildversion
Other
R8

Recommendations

Enable compression (gzip/brotli) to improve performance