Open
Cached
·
5h ago
15
Headers
HTTP Security Headers
Status
Strict-Transport-Security
Excellent
max-age=31536000; includeSubDomains; preload
Content-Security-Policy
Good
base-uri; block-all-mixed-content; connect-src; +15 more
base-uri 'none';block-all-mixed-content;connect-src 'self' https://statics.teams.cdn.live.net login.microsoftonline.com teams.microsoft.com teams.live.com teams.events.data.microsoft.com browser.events.data.microsoft.com *.asm.skype.com c.bing.com *.clarity.ms config.teams.microsoft.com consentreceiverfd-prod.azurefd.net;default-src 'none';font-src static2.sharepointonline.com;form-action 'none';frame-ancestors 'self';frame-src 'self' login.microsoftonline.com login.live.com;img-src https://statics.teams.cdn.live.net 'self' teams.live.com;manifest-src 'none';media-src https://statics.teams.cdn.live.net;object-src 'none';require-trusted-types-for 'script';script-src 'report-sample' 'nonce-HjOShppVUj+w5HoJ/HqUCQ==' https://statics.teams.cdn.live.net res.cdn.office.net 'self' wcpstatic.microsoft.com;style-src 'self' static2.sharepointonline.com 'unsafe-inline';trusted-types @msteams/gather @msteams/core-services-telemetry-worker#TelemetryWorker default dompurify;worker-src 'self';report-uri https://csp.microsoft.com/report/teams-web-r4?v=25111315546&env=life&exp=gather;
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Strengthen CSP by removing 'unsafe-eval'
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
Performance Headers
1 headers
Connection
Performance
close
Caching Headers
2 headers
Cache-Control
Caching
no-store, no-transform, must-revalidate, no-cache
Expires
Caching
Sun, 28 Dec 2025 03:25:58 GMT
Content Headers
2 headers
Content-Length
Content
53606
Content-Type
Content
text/html; charset=utf-8
Server Headers
0 headers
No server headers found
CORS Headers
0 headers
No CORS headers found
Cookies Headers
0 headers
No cookies headers found
Other Headers
6 headers
Date
Other
Mon, 29 Dec 2025 03:25:58 GMT
Requestid
Other
601405086e493b233319d01b476469de
Timing-Allow-Origin
Other
*
X-Cache
Other
CONFIG_NOCACHE
X-Msedge-Ref
Other
Ref A: C6EAD53EC5864FB6A282B5FC70AA915B Ref B: BL2EDGE1309 Ref C: 2025-12-29T03:25:58Z
X-Ring-Info
Other
web: general [assigned];
Recommendations
Enable compression (gzip/brotli) to improve performance
Analysis completed in 669ms