airnewzealand.co.nz | Analytics by SecurityHeaders

HTTP Headers report for airnewzealand.co.nz

Header Name Header Data
HTTP status code 200
Content-Type text/html; charset=UTF-8
X-Xss-Protection 1; mode=block
X-Frame-Options SAMEORIGIN
X-Content-Type-Options nosniff
Last-Modified Thu, 17 Apr 2025 03:48:33 GMT
Strict-Transport-Security max-age=31536000
X-Cache Miss from cloudfront
Cache-Control no-cache, no-store, must-revalidate, pre-check=0, post-check=0
Content-Security-Policy block-all-mixed-content; default-src 'self'; base-uri 'self'; form-action 'self' flightbookings.airnewzealand.ca flightbookings.airnewzealand.cn flightbookings.airnewzealand.co.jp flightbookings.airnewzealand.co.kr flightbookings.airnewzealand.co.nz flightbookings.airnewzealand.co.uk flightbookings.airnewzealand.com flightbookings.airnewzealand.com.au flightbookings.airnewzealand.com.cn flightbookings.airnewzealand.com.hk flightbookings.airnewzealand.com.sg flightbookings.airnewzealand.com.tw flightbookings.airnewzealand.eu flightbookings.airnewzealand.hk flightbookings.airnewzealand.jp flightbookings.airnewzealand.kr flightbookings.airnewzealand.pf flightbookings.airnewzealand.tw flightbookings.grabaseat.co.nz govtbookings.airnewzealand.co.nz au-connect.authsignal.com auth.identity.airnewzealand.com auth.identity.qual.airnewzealand.com checkoutshopper-test.adyen.com checkoutshopper-live-au.adyen.com; script-src 'self' p-airnz.com 'unsafe-inline' 'unsafe-eval' *.googleapis.com *.gstatic.com *.google.com *.ggpht.com *.googleusercontent.com www.youtube.com s.ytimg.com s.wayin.com xd.wayin.com x.wayin.com eu-x.wayin.com s.engagesciences.com display.engagesciences.com display.wayin.com www.everestjs.net *.demdex.net www.google-analytics.com analytics.google.com tagmanager.google.com www.googletagmanager.com *.doubleclick.net www.googleadservices.com cdn-assets-prod.s3.amazonaws.com *.optimizely.com optimizely-hrd.appspot.com optimizely.s3.amazonaws.com s.swiftypecdn.com upgrade.plusgrade.com md-scp.kampyle.com sbt-prod.kampyle.com nebula-cdn.kampyle.com udc-neb.kampyle.com analytics-fe.digital-cloud-syd1.medallia.com.au static.hotjar.com script.hotjar.com yourir.info *.airnewzealand.co.nz musculahq.appspot.com dnn506yrbagrg.cloudfront.net xsell.expedia.com ddc.optimahub.com www.newzealand.com https://widget.timatic.iata.org/scripts/iata-timatic-widget-live.js oc-cdn-public-oce.azureedge.net https://unpkg.com/acs_webchat-chat-adapter@0.0.35-beta.20/dist/chat-adapter.js cdn-au.onetrust.com; style-src 'unsafe-inline' p-airnz.com fonts.googleapis.com tagmanager.google.com s.swiftypecdn.com upgrade-cdn-prd.plusgrade.com static.hotjar.com script.hotjar.com yourir.info 'self' oc-cdn-public-oce.azureedge.net; img-src https: data: static.hotjar.com script.hotjar.com; font-src p-airnz.com fonts.googleapis.com fonts.gstatic.com dhm5hy2vn8l0l.cloudfront.net script.hotjar.com 'self' data: *.cdn.office.net; media-src 'self' p-airnz.com data:; frame-src 'self' *.google.com auth.identity.airnewzealand.com identity.airnewzealand.com au-connect.authsignal.com nz.fltmaps.com airpointscalculator.co.nz www.youtube.com airnz.wufoo.com xd.wayin.com x.wayin.com eu-x.wayin.com display.engagesciences.com www.everestjs.net pixel.everesttech.net *.demdex.net *.doubleclick.net www.googletagmanager.com *.cdn-pci.optimizely.com nebula-cdn.kampyle.com vars.hotjar.com *.airnewzealand.co.nz auth.airnewzealand.co.nz sec.windcave.com uat.windcave.com checkoutshopper-test.adyen.com checkoutshopper-live-au.adyen.com hotels.airnewzealand.co.nz oc-cdn-public-oce.azureedge.net blob: comms.omnichannelengagementhub.com customervoice.microsoft.com airnz-cargo.chooose.today airnz-corporate.chooose.today emissions-platform.airnewzealand.co.nz; worker-src blob:; connect-src 'self' api.airnz.io api.airnz.ai *.googleapis.com *.google.com *.gstatic.com auth.airnewzealand.co.nz identity.airnewzealand.com *.demdex.net *.tt.omtrdc.net www.google-analytics.com region1.google-analytics.com region1.analytics.google.com analytics.google.com stats.g.doubleclick.net adservice.google.com www.google.com *.optimizely.com s.swiftypecdn.com search-api.swiftype.com md-scp.kampyle.com sbt-prod.kampyle.com nebula-cdn.kampyle.com udc-neb.kampyle.com analytics-fe.digital-cloud-syd1.medallia.com.au https://*.hotjar.com https://*.hotjar.io wss://*.hotjar.com https://*.sentry.io yourir.info muscula.herokuapp.com sec.windcave.com uat.windcave.com checkoutshopper-test.adyen.com checkoutshopper-live-au.adyen.com tourismnz.sc.omtrdc.net https://widget.timatic.iata.org/api/ unq0355446423e84eb397bc71189d78d-crm6.omnichannelengagementhub.com browser.pipe.aria.microsoft.com *.omnichannelengagementhub.com *.au.omnichannelengagementhub.com https://*.trouter.skype.com wss://*.trouter.skype.com edge.skype.com *.communication.azure.com ocsdk-prod.azureedge.net cdn-au.onetrust.com geolocation.onetrust.com privacyportal-au.onetrust.com; object-src 'none'; frame-ancestors 'self' www.airnewzealand.com.au www.airnewzealand.com www.airnewzealand.ca www.airnewzealand.co.uk www.airnewzealand.eu www.airnewzealand.co.jp www.airnewzealand.jp www.airnewzealand.com.sg www.airnewzealand.pf www.airnewzealand.cn www.airnewzealand.com.cn www.airnewzealand.hk www.airnewzealand.com.hk www.airnewzealand.tw www.airnewzealand.com.tw www.airnewzealand.co.kr www.airnewzealand.kr flightbookings.airnewzealand.ca flightbookings.airnewzealand.cn flightbookings.airnewzealand.co.jp flightbookings.airnewzealand.co.kr flightbookings.airnewzealand.co.nz govtbookings.airnewzealand.co.nz flightbookings.airnewzealand.co.uk flightbookings.airnewzealand.com.au flightbookings.airnewzealand.com flightbookings.airnewzealand.com.cn flightbookings.airnewzealand.com.hk flightbookings.airnewzealand.com.sg flightbookings.airnewzealand.com.tw flightbookings.airnewzealand.eu flightbookings.airnewzealand.hk flightbookings.airnewzealand.jp flightbookings.airnewzealand.kr flightbookings.airnewzealand.pf flightbookings.airnewzealand.tw flightbookings.grabaseat.co.nz; report-uri /csp-report
Permissions-Policy geolocation=(self "https://p-airnz.com"), camera=(), fullscreen=(self "https://www.youtube.com"), accelerometer=(), gyroscope=(), magnetometer=(), microphone=(), midi=(), payment=(), screen-wake-lock=(), sync-xhr=(*), usb=(), web-share=(), clipboard-read=(), clipboard-write=()
Via 1.1 a5b856e4b06666713c5cc47a5b2ec7ae.cloudfront.net (CloudFront)
Alt-Svc h3=":443"; ma=86400
X-Amz-Cf-Id pp-KmDrb9WGOhI9YnUQyppXaN-CAR6H8l-AylV6QgYX_P2-9Q3D_sA==
Server nginx
Date Sat, 19 Apr 2025 12:49:34 GMT
Referrer-Policy strict-origin
X-Amz-Cf-Pop AMS1-P2
Connection keep-alive
Vary Accept-Encoding
Expires 0

About the tool

By using SecurityHeaders.info, you can quickly identify missing or misconfigured headers and take steps to secure your website, improving both security and user confidence.

This tool is widely used by developers, security professionals, and organizations to ensure their websites adhere to best practices in web security.

We also have another analytic tool that is used for identifying popularity metrics, general information about the business, finding similar products and competitors, and much more.

Watch it now at TrustRadar