Open
Cached
·
just now
21
Headers
Detected Technologies from Headers
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=2592000
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
Performance Headers
Connection
close
Transfer-Encoding
chunked
connection: close transfer-encoding: chunked
Caching Headers
Cache-Control
no-cache, no-store
Pragma
no-cache
cache-control: no-cache, no-store pragma: no-cache
Content Headers
Content-Type
text/html; charset=utf-8
content-type: text/html; charset=utf-8
CORS Headers
Access-Control-Expose-Headers
X-Ems-Correlationid,X-Ems-SessionId
access-control-expose-headers: X-Ems-Correlationid,X-Ems-SessionId
Cookies Headers
Other Headers
Date
Thu, 09 Apr 2026 08:54:43 GMT
Request-Context
appId=cid-v1:b8b1f729-292d-4d99-ae99-6e39faf60ad8
X-Buildversion
v20260408.2.official
X-Cache
CONFIG_NOCACHE
X-Ems-Correlationid
38de1577-c6a2-41fe-bdb3-24b6e6150d18
X-Ems-Csp-Header-Version
5
X-Ems-Envname
emerald-prod-eus2
X-Ems-Instname
PD1SDWK001658
X-Ems-Sessionid
38de1577-c6a2-41fe-bdb3-24b6e6150d18
date: Thu, 09 Apr 2026 08:54:43 GMT request-context: appId=cid-v1:b8b1f729-292d-4d99-ae99-6e39faf60ad8 x-azure-ref: 20260409T085443Z-155cf88b48fm6fllhC1IADk23g00000001a00000000053es x-buildversion: v20260408.2.official x-cache: CONFIG_NOCACHE x-ems-correlationid: 38de1577-c6a2-41fe-bdb3-24b6e6150d18 x-ems-csp-header-version: 5 x-ems-envname: emerald-prod-eus2 x-ems-instname: PD1SDWK001658 x-ems-sessionid: 38de1577-c6a2-41fe-bdb3-24b6e6150d18
Recommendations
Enable compression (gzip/brotli) to improve performance
Consider removing X-Powered-By header to hide server technology