20 Headers

Detected Technologies from Headers

HTTP Security Headers

Status
Strict-Transport-Security
Excellent
max-age=31536000; includeSubDomains; preload
Content-Security-Policy
Good
default-src; connect-src; font-src; +6 more Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Excellent
DENY
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Present
origin
Permissions-Policy
Missing
Not configured
Recommendations
  • Strengthen CSP by removing 'unsafe-eval'
  • Consider adding Permissions-Policy to control browser features

Performance Headers

Connection
Performance
close
Transfer-Encoding
Performance
chunked
Vary
Performance
accept-encoding

Caching Headers

Cache-Control
Caching
no-store

Content Headers

Content-Language
Content
en-US-x-lvariant-USA
Content-Type
Content
text/html;charset=UTF-8

Server Headers

Server
Server
Apple

CORS Headers

No CORS headers found

Cookies Headers

Set-Cookie
Cookies

Other Headers

Date
Other
Wed, 01 Apr 2026 14:26:53 GMT
Host
Other
appleid.apple.com
Scnt
Other
AAAA-jAyODE4OEEzMkFCNTMwQTg4QzdFQTVGREQwRTE1MzlCREE3OTA5MzU2RERFN0Y3MjYxOTM2NjM5OTI0QzNDNEREQzlCQjg2RUJFM0QxNkY0MkRDQjVFQTkxQkY1Qzk3M0E1QjcwQkNFMzIzMEJGOTA0M0M5NjM3OEJEQUY4NzJDM0QxRjAyRkQwQUM5RTQ5MUQ4OTAxM0JBRjAxRTQ1NTQwOUJBNUI1ODA5RTE5OUE4RjJDRkU2QkRGNzZFNkIxQTQyOEFEMTQ5QTU0QjM5RjA2QzA3QUU3OEI4OUM5MzNGQ0Q0Q0RCQjk2MERGRTA1OXwxAAABnUl-jBg0XEqodSZbqARsYfj6cwjBsKqr8YvsOR2n0n38slfVMsKzJxUQi1zEAAtVdYspDfXLqvoDTTdMDLHxGQ9ZdCRpZvE0TQEa9RZpNzW2x1APAQ
X-Apple-I-Request-Id
Other
d45aaed1-2dd6-11f1-8ae2-057fb7cd2f95
X-Apple-Id-Session-Id
Other
028188A32AB530A88C7EA5FDD0E1539BDA7909356DDE7F7261936639924C3C4DDC9BB86EBE3D16F42DCB5EA91BF5C973A5B70BCE3230BF9043C96378BDAF872C3D1F02FD0AC9E491D89013BAF01E455409BA5B5809E199A8F2CFE6BDF76E6B1A428AD149A54B39F06C07AE78B89C933FCD4CDBB960DFE059
X-Buildversion
Other
R7_1

Recommendations

Enable compression (gzip/brotli) to improve performance