20 Headers

Detected Technologies from Headers

HTTP Security Headers

Status
Strict-Transport-Security
Excellent
max-age=31536000; includeSubDomains; preload
Content-Security-Policy
Good
default-src; connect-src; font-src; +6 more Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Excellent
DENY
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Present
origin
Permissions-Policy
Missing
Not configured
Recommendations
  • Strengthen CSP by removing 'unsafe-eval'
  • Consider adding Permissions-Policy to control browser features

Performance Headers

Connection
Performance
close
Transfer-Encoding
Performance
chunked
Vary
Performance
accept-encoding

Caching Headers

Cache-Control
Caching
no-store

Content Headers

Content-Language
Content
en-US-x-lvariant-USA
Content-Type
Content
text/html;charset=UTF-8

Server Headers

Server
Server
Apple

CORS Headers

No CORS headers found

Cookies Headers

Set-Cookie
Cookies

Other Headers

Date
Other
Fri, 10 Apr 2026 23:07:37 GMT
Host
Other
account.apple.com
Scnt
Other
AAAA-kUyRURENjE5RjIzRjYwODUyNEJFMDYxNTZERjIyM0VGRkRGQ0VBQjIwQjc2MTJCQzlGNDE4QUY3M0Q4NDYxRDI2MTk5OURGNjhDNDQ3RUE3MjQwMDVBMTk4MzM5MUQwOTE2REM4MjhDNjI1NDYwQkM0Q0RFRTI4MTUwMUM0MUQxODZGNDIyRjc1NzlCRkI3QkIyNDJERDcwRUY0MDcwOEM4MjFDOTZBMjY5NkU1MUI5NDMxMTc4MEM4OEZGQThCQ0E3RTlBMDk5MEU0QjZDRDI0MjQ1M0EyNzIyRjVCMDQ4OEMxOUYwRUVDODJDRTdFNHwxAAABnXm0hjeRY6nyF5xO98qrrY7HXkbWmSlX0COy55jikYg5oyEV97NL0dGoWC5UAA-P_qPWmZw_SiLg3NA-XkTmcwKnP35JdpxusB9JElauyP5SRz9cvA
X-Apple-I-Request-Id
Other
10d4e300-3532-11f1-a7e3-bf23c0eda5ed
X-Apple-Id-Session-Id
Other
E2EDD619F23F608524BE06156DF223EFFDFCEAB20B7612BC9F418AF73D8461D261999DF68C447EA724005A1983391D0916DC828C625460BC4CDEE281501C41D186F422F7579BFB7BB242DD70EF40708C821C96A2696E51B94311780C88FFA8BCA7E9A0990E4B6CD242453A2722F5B0488C19F0EEC82CE7E4
X-Buildversion
Other
R8_2

Recommendations

Enable compression (gzip/brotli) to improve performance