23 Headers

HTTP Security Headers

Status
Strict-Transport-Security
Good
max-age=31536000; includeSubDomains
Content-Security-Policy
Weak
frame-ancestors
X-Frame-Options
Good
SAMEORIGIN
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Consider adding 'preload' to HSTS for maximum security
  • Significantly strengthen CSP directives
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

Performance Headers

3 headers
Connection
Performance
close
Transfer-Encoding
Performance
chunked
Vary
Performance
Accept-Encoding

Caching Headers

2 headers
Cache-Control
Caching
max-age=0, must-revalidate, private
Expires
Caching
Mon, 26 Jan 2026 08:54:06 GMT

Content Headers

1 headers
Content-Type
Content
text/html; charset=UTF-8

Server Headers

1 headers
Server
Server
cloudflare

CORS Headers

0 headers
No CORS headers found

Cookies Headers

1 headers
Set-Cookie
Cookies
__cf_bm=I08mElJpg4EQVveavC4BAXSKLt3XjYqObGYc3GGOTQg-1769417646-1.0.1.1-evE60uiLI2pS1cB6xRrlpgGGDkqF4FAqBjCa1ObkChK4czv.4WsoegqSdkLhybgkH5Uq25ER0CzPHRKQCNyWOiutqqW8WpCwKzWTny70cJCFOLZAIEXWxmRnsCHSH1c8; path=/; expires=Mon, 26-Jan-26 09:24:06 GMT; domain=.chess.com; HttpOnly; Secure; SameSite=None

Other Headers

11 headers
Alt-Svc
Other
h3=":443"; ma=86400
Cf-Cache-Status
Other
DYNAMIC
Cf-Ray
Other
9c3ec8a069d512f0-IAD
Date
Other
Mon, 26 Jan 2026 08:54:06 GMT
Link
Other
</bundles/app/css/design-system.client.52647960.css>; rel="preload"; as="style",</bundles/app/css/main.client.2c597fd6.css>; rel="preload"; as="style",</bundles/app/css/sprites.client.44c69c36.css>; rel="preload"; as="style",</bundles/app/css/alerts.client.09b67b9a.css>; rel="preload"; as="style",</bundles/app/css/navigation-legacy.client.a9af2fee.css>; rel="preload"; as="style",</bundles/app/css/global.client.68b5e76f.css>; rel="preload"; as="style",</bundles/app/css/navigation-footer.client.18083854.css>; rel="preload"; as="style",</bundles/app/css/content.client.830842b4.css>; rel="preload"; as="style",</bundles/app/css/layout.client.8f9fc6cf.css>; rel="preload"; as="style",</bundles/app/css/index.client.08aa3aef.css>; rel="preload"; as="style",</bundles/app/css/landing-page.client.5ba02b22.css>; rel="preload"; as="style"
Nel
Other
{"success_fraction":1,"report_to":"cf-nel","max_age":604800}
Report-To
Other
{"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=2fGRc42Y%2FukyF3kQLGv3YADmk6uZ3s0CuGKVKFo1MWyJt95jClbpt7coc1OsT%2FXZsZNSeeOidFCWxvOznVV7w4n7t4rBQpLrPzvGGzj2%2F%2FX33bfoMvr5%2BpLmPC0EOm8%3D"}],"group":"cf-nel","max_age":604800}
X-Chesscom-Matched
Other
web_index
X-Chesscom-Request-Id-Cdn
Other
9c3ec8a069d512f0-IAD
X-Chesscom-Request-Id-Lb
Other
1f75bd8c54c68d793315c86a76c03b9c
X-Chesscom-Version
Other
20260123114856

Recommendations

Enable compression (gzip/brotli) to improve performance