Open
Cached
·
just now
16
Headers
HTTP Security Headers
Status
Strict-Transport-Security
Excellent
max-age=31536000; includeSubDomains; preload
X-Frame-Options
Excellent
DENY
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Significantly strengthen CSP directives
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
Performance Headers
Connection
close
connection: close
Caching Headers
Etag
"1f2-4cb1d3b2ae680-gzip"
Last-Modified
Wed, 03 Oct 2012 01:05:14 GMT
etag: "1f2-4cb1d3b2ae680-gzip" last-modified: Wed, 03 Oct 2012 01:05:14 GMT
Content Headers
Content-Length
498
Content-Type
text/html
content-length: 498 content-type: text/html
Server Headers
Server
Apple
server: Apple
CORS Headers
No CORS headers found
Cookies Headers
Other Headers
Date
Sun, 12 Apr 2026 10:16:14 GMT
Reporting-Endpoints
aos-csp-error="https://www.apple.com/shop/mdp/api/csp-error"
Server-Timing
app;dur=0.010053, dc;desc=ucp5
X-Nxid
41db44e66be3f8d5ed196a41fe2acf5d
X-Shred
1088c8302bb3f6dc082f7a6e33433742
date: Sun, 12 Apr 2026 10:16:14 GMT reporting-endpoints: aos-csp-error="https://www.apple.com/shop/mdp/api/csp-error" server-timing: app;dur=0.010053, dc;desc=ucp5 x-nxid: 41db44e66be3f8d5ed196a41fe2acf5d x-shred: 1088c8302bb3f6dc082f7a6e33433742
Recommendations
Enable compression (gzip/brotli) to improve performance
Add Cache-Control header to optimize caching