Cached · 1h ago
26 Headers

HTTP Security Headers

Status
Strict-Transport-Security
Present
max-age=63072000; includeSubdomains; preload
Content-Security-Policy
Basic
default-src; script-src; style-src; +5 more Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Good
SAMEORIGIN
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Increase HSTS max-age to at least 1 year and add includeSubDomains
  • Improve CSP by adding more specific directives and removing 'unsafe-inline'
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

Performance Headers

Accept-Ranges
Performance
bytes
Connection
Performance
close
Vary
Performance
Accept-Encoding

Caching Headers

Age
Caching
0
Cache-Control
Caching
public, max-age=300
Etag
Caching
"2e536-659a7c817240c"
Expires
Caching
Sat, 22 Aug 2026 19:48:43 GMT
Last-Modified
Caching
Sat, 22 Aug 2026 19:30:11 GMT

Content Headers

Content-Length
Content
189750
Content-Type
Content
text/html;charset=utf-8

Server Headers

No server headers found

CORS Headers

No CORS headers found

Cookies Headers

No cookies headers found

Other Headers

Afdforward
Other
Beta Prod
Afdgeo
Other
US
Afdrsaemplatform
Other
V11
Afdrsaemversion
Other
V1
Date
Other
Sat, 22 Aug 2026 19:55:40 GMT
X-Azure-Ref
Other
20260822T195539Z-164c5c96d8bs5h4rhC1IADzeyc0000000bp0000000007bbb
X-Cache
Other
TCP_REMOTE_HIT
X-Cache-Info
Other
L2_T1
X-Fd-Int-Roxy-Purgeid
Other
0
X-Served-By
Other
cache-iad-kiad7000151-IAD
X-Timer
Other
S1787427823.352793,VS0,VS0,VE147
X-Vhost
Other
publish

Recommendations

Enable compression (gzip/brotli) to improve performance