Open
Cached
·
just now
23
Headers
Detected Technologies from Headers
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=15552001;includeSubDomains; preload
X-Frame-Options
Good
SAMEORIGIN
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Present
same-origin
Permissions-Policy
Present
microphone=(), camera=()
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Significantly strengthen CSP directives
Performance Headers
Connection
close
Transfer-Encoding
chunked
Vary
*
connection: close transfer-encoding: chunked vary: *
Caching Headers
Cache-Control
public, max-age=0, s-maxage=2678400
Etag
"5e3aa2fd-cd1d-49f4-878a-b3b81a732df8"
Expires
Mon, 07 Sep 2026 20:10:49 GMT
Last-Modified
Mon, 07 Sep 2026 20:10:50 GMT
cache-control: public, max-age=0, s-maxage=2678400 etag: "5e3aa2fd-cd1d-49f4-878a-b3b81a732df8" expires: Mon, 07 Sep 2026 20:10:49 GMT last-modified: Mon, 07 Sep 2026 20:10:50 GMT
Content Headers
Content-Type
text/html; charset=utf-8
content-type: text/html; charset=utf-8
Server Headers
server: x-aspnet-version: x-powered-by:
CORS Headers
Access-Control-Allow-Origin
https://www.eastspring25.com
access-control-allow-origin: https://www.eastspring25.com
Cookies Headers
Other Headers
Date
Mon, 07 Sep 2026 20:10:50 GMT
X-Iinfo
38-183658208-183658248 NNNY CT(224 449 0) RT(1788811849638 180) q(0 0 0 5) r(8 8) U12
date: Mon, 07 Sep 2026 20:10:50 GMT x-cdn: Imperva x-iinfo: 38-183658208-183658248 NNNY CT(224 449 0) RT(1788811849638 180) q(0 0 0 5) r(8 8) U12
Recommendations
Enable compression (gzip/brotli) to improve performance
Consider removing X-Powered-By header to hide server technology