33 Headers

HTTP Security Headers

Status
Strict-Transport-Security
Present
max-age=10886400; includeSubdomains
Content-Security-Policy
Basic
child-src; connect-src; default-src; +9 more Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Good
SAMEORIGIN
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Increase HSTS max-age to at least 1 year and add includeSubDomains
  • Improve CSP by adding more specific directives and removing 'unsafe-inline'
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

Performance Headers

Connection
Performance
close, Transfer-Encoding
Transfer-Encoding
Performance
chunked

Caching Headers

Cache-Control
Caching
no-store, max-age=0, private, must-revalidate
Expires
Caching
Thu, 01 Jan 1970 00:00:00 GMT

Content Headers

Content-Type
Content
text/html;charset=utf-8

Server Headers

Server
Server
nginx

CORS Headers

No CORS headers found

Cookies Headers

Set-Cookie
Cookies

Other Headers

Accept-Ch
Other
Sec-CH-Device-Memory, Sec-CH-DPR, ECT, Sec-CH-UA-Platform-Version, Sec-CH-Viewport-Width, Sec-CH-Device-Memory, Sec-CH-DPR, ECT, Sec-CH-UA-Platform-Version, Sec-CH-Viewport-Width
Accept-Ch-Lifetime
Other
31536000
Akamai-Request-Bc
Other
[a=23.52.15.75,b=874968273,c=g,n=US_VA_ASHBURN,o=20940],[c=c,n=US_VA_ASHBURN,o=20940],[a=237,c=o]
Alt-Svc
Other
h3=":443"; ma=93600
Cachestatus
Other
on
Date
Other
Mon, 27 Apr 2026 09:50:45 GMT
Origin-Trial
Other
AkOekvxwprBLSP7I2nhyRn5yZGt9lTJN6UIYziFKVYg5OhlzmlNDciWbBWkEQ5TYPz+aqsuIUT2pPEjPUD5dFAsAAABneyJvcmlnaW4iOiJodHRwczovL2FpcmJuYi5jb206NDQzIiwiZmVhdHVyZSI6IlByaW9yaXR5SGludHNBUEkiLCJleHBpcnkiOjE2NDc5OTM1OTksImlzU3ViZG9tYWluIjp0cnVlfQ==
Server-Timing
Other
ingress;dur=55, upstream;dur=55, cdn-cache; desc=MISS, edge; dur=42, origin; dur=61
Status
Other
200 OK
X-Airbnb-Everest-Device-Id
Other
1777283445.EAODFmMDI1NWIzODFmZD.e7_vR0gmPFXfLq4s-tWJPxa7L8nMV5_VHyLU4ZfcNXw
X-Airbnb-Internal-Trace-Id
Other
hmw2q4Lz9SwrK1DWFi4rHQ==
X-Airbnb-Kraken-Flush-Body
Other
1
X-Airbnb-Sureride
Other
c1a1o.0.4b0f3417.1777283445.3426f4d1%%i1c1o%%t1d1o.hmw2q4Lz9SwrK1DWFi4rHQ==%%e1f1o.E2IHEUl1EAUJMgtdDy4GAxRiGQ%%t1d1o.hmw2q4Lz9SwrK1DWFi4rHQ==%%h1
X-Browser-Type
Other
unknown
X-Envoy-Upstream-Service-Time
Other
55
X-Erf-Bev-Bev
Other
1777283445_EAMDUyNzFhM2I1Yz
X-Erf-Bev-Bev-Is-Generated
Other
1
X-Instrumentation
Other
airbnb
X-Kraken-Loop-Name
Other
core-guest-loop
X-Server-Lifecycle-Phase
Other
running

Recommendations

Enable compression (gzip/brotli) to improve performance