Open
Cached
·
just now
23
Headers
HTTP Security Headers
Status
Strict-Transport-Security
Good
max-age=31536000 ; includeSubDomains
Content-Security-Policy
Weak
frame-ancestors
X-Frame-Options
Good
SAMEORIGIN
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Consider adding 'preload' to HSTS for maximum security
- • Significantly strengthen CSP directives
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
Performance Headers
1 headers
Connection
Performance
close
Caching Headers
3 headers
Cache-Control
Caching
no-store, no-cache, must-revalidate, proxy-revalidate
Expires
Caching
0
Pragma
Caching
no-cache
Content Headers
2 headers
Content-Length
Content
1774
Content-Type
Content
text/html
Server Headers
1 headers
Server
Server
ant-23c1fea0
CORS Headers
1 headers
Access-Control-Allow-Origin
Cors
https://www.bcbsdirect.com
Cookies Headers
1 headers
Set-Cookie
Cookies
bm_sz=3430D7BB2253B783ACA31F7354FE5BA4~YAAQB97aFyFKw2ybAQAAqoXNcR79IAT8WCx58jIfYPxExgvQCXrC1MR1KaXA6eWH5+Zqp3rI+Esp/UnY+3L+ygvbx9Fmu7XdL8vjAm4GgT3QjGBUf+Ok0xFfAncicG4l1AfKhJYflTSE2x12Mk0PX1hJe2GyacjE1WKsj+ah7lNXDZqkGFdqO6TrWshTjc/m59/8vZCshWMOivgRYKxfFPslR4F33SOeu/Xyum6i8QCj2KwjTFD/9JGmHzycarSd6tdxIYWKUg4oPsQDKB/oUMAe9cEBZ3PxbDNffKN9A66BSXJuW+4EePCe/hzylH0qV39dvIEvhibV45pFL0bfTctN26lunYEoum1bh/84kA==~4468786~3225668; Domain=.bcbsdirect.com; Path=/; Expires=Wed, 31 Dec 2025 04:27:33 GMT; Max-Age=14400
Other Headers
9 headers
Date
Other
Wed, 31 Dec 2025 00:27:33 GMT
Server-Timing
Other
ak_p; desc="1767140852991_400219655_211400589_14104_21922_0_4_-";dur=1
Surrogate-Control
Other
no-store
X-Akamai-Transformed
Other
9 685 0 pmb=mTOE,2
X-Dns-Prefetch-Control
Other
off
X-Download-Options
Other
noopen
X-Request-Id
Other
09d80c0a6e8726486fd9db0ec4c20ae2
X-Rid
Other
438bd098-06b1-4cba-9ef8-e5fa44dda295
X-Tcp-Info
Other
2c95
Recommendations
Enable compression (gzip/brotli) to improve performance