Cached · just now
33 Headers

HTTP Security Headers

Status
Strict-Transport-Security
Present
max-age=10886400; includeSubdomains
Content-Security-Policy
Basic
child-src; connect-src; default-src; +9 more Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Good
SAMEORIGIN
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Increase HSTS max-age to at least 1 year and add includeSubDomains
  • Improve CSP by adding more specific directives and removing 'unsafe-inline'
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

Performance Headers

Connection
Performance
close, Transfer-Encoding
Transfer-Encoding
Performance
chunked

Caching Headers

Cache-Control
Caching
no-store, max-age=0, private, must-revalidate
Expires
Caching
Thu, 01 Jan 1970 00:00:00 GMT

Content Headers

Content-Type
Content
text/html;charset=utf-8

Server Headers

Server
Server
nginx

CORS Headers

No CORS headers found

Cookies Headers

Set-Cookie
Cookies

Other Headers

Accept-Ch
Other
Sec-CH-Device-Memory, Sec-CH-DPR, ECT, Sec-CH-UA-Platform-Version, Sec-CH-Viewport-Width, Sec-CH-Device-Memory, Sec-CH-DPR, ECT, Sec-CH-UA-Platform-Version, Sec-CH-Viewport-Width
Accept-Ch-Lifetime
Other
31536000
Akamai-Request-Bc
Other
[a=23.220.105.216,b=132682669,c=g,n=US_VA_ASHBURN,o=20940],[c=c,n=US_VA_ASHBURN,o=20940],[a=247,c=o]
Alt-Svc
Other
h3=":443"; ma=93600
Cachestatus
Other
on
Date
Other
Mon, 27 Apr 2026 07:19:08 GMT
Origin-Trial
Other
AkOekvxwprBLSP7I2nhyRn5yZGt9lTJN6UIYziFKVYg5OhlzmlNDciWbBWkEQ5TYPz+aqsuIUT2pPEjPUD5dFAsAAABneyJvcmlnaW4iOiJodHRwczovL2FpcmJuYi5jb206NDQzIiwiZmVhdHVyZSI6IlByaW9yaXR5SGludHNBUEkiLCJleHBpcnkiOjE2NDc5OTM1OTksImlzU3ViZG9tYWluIjp0cnVlfQ==
Server-Timing
Other
ingress;dur=66, upstream;dur=66, cdn-cache; desc=MISS, edge; dur=50, origin; dur=73
Status
Other
200 OK
X-Airbnb-Everest-Device-Id
Other
1777274348.EANzJjYjZmNzdhNmNlNW.NnW2gL1wK_2aH074k7zE-d67B0a8RPWPnEzdrB7y2DU
X-Airbnb-Internal-Trace-Id
Other
UE2d3dUWHw9F8xnwueXcdQ==
X-Airbnb-Kraken-Flush-Body
Other
1
X-Airbnb-Sureride
Other
c1a1o.0.d869dc17.1777274348.7e893ad%%i1c1o%%t1d1o.UE2d3dUWHw9F8xnwueXcdQ==%%e1f1o.E2IHEUl1EAUJMgtdDycGChRiGQ%%t1d1o.UE2d3dUWHw9F8xnwueXcdQ==%%h1
X-Browser-Type
Other
unknown
X-Envoy-Upstream-Service-Time
Other
66
X-Erf-Bev-Bev
Other
X-Erf-Bev-Bev-Is-Generated
Other
0
X-Instrumentation
Other
airbnb
X-Kraken-Loop-Name
Other
core-guest-loop
X-Server-Lifecycle-Phase
Other
running

Recommendations

Enable compression (gzip/brotli) to improve performance