Header Name | Header Data |
---|---|
HTTP status code | 200 |
X-Response-With | YMail |
Content-Security-Policy | default-src 'none'; script-src yastatic.net https://*.static-dev.mail.yandex.net/s3/psf/ 'unsafe-eval' 'nonce-VljiX1p91K66TmQ9IxAX/w==' 'self' 'unsafe-inline' mc.yandex.ru mc.yandex.az mc.yandex.by mc.yandex.co.il mc.yandex.com mc.yandex.com.am mc.yandex.com.ge mc.yandex.com.tr mc.yandex.ee mc.yandex.fr mc.yandex.kg mc.yandex.kz mc.yandex.lt mc.yandex.lv mc.yandex.md mc.yandex.ru mc.yandex.tj mc.yandex.tm mc.yandex.ua mc.yandex.uz mc.webvisor.com mc.webvisor.org mc.admetrica.ru yastatic.net ad.adriver.ru content.adriver.ru ev.adriver.ru; style-src yastatic.net https://*.static-dev.mail.yandex.net/s3/psf/ 'unsafe-inline' 'self' fonts.googleapis.com; font-src yastatic.net https://*.static-dev.mail.yandex.net/s3/psf/ fonts.gstatic.com; media-src yastatic.net https://*.static-dev.mail.yandex.net/s3/psf/ 'unsafe-inline' 'self' storage.yandexcloud.net storage.cloud-preprod.yandex.net s3.mds.yandex.net https://360-marketing-specials-public.s3.yandex.net; img-src yastatic.net https://*.static-dev.mail.yandex.net/s3/psf/ 'self' data: blob: mc.yandex.ru mc.yandex.az mc.yandex.by mc.yandex.co.il mc.yandex.com mc.yandex.com.am mc.yandex.com.ge mc.yandex.com.tr mc.yandex.ee mc.yandex.fr mc.yandex.kg mc.yandex.kz mc.yandex.lt mc.yandex.lv mc.yandex.md mc.yandex.ru mc.yandex.tj mc.yandex.tm mc.yandex.ua mc.yandex.uz mc.webvisor.com mc.webvisor.org mc.admetrica.ru yastatic.net downloader.disk.yandex.com downloader.disk.yandex.net yandex.ru favicon.yandex.net storage.yandexcloud.net storage.cloud-preprod.yandex.net s3.mds.yandex.net yc-www-community-images.storage.yandexcloud.net https://360-marketing-specials-public.s3.yandex.net avatars.mds.yandex.net ad.adriver.ru content.adriver.ru ev.adriver.ru *.storage.yandex.net *.disk.yandex.net; connect-src yandex.ru mc.yandex.ru mc.yandex.az mc.yandex.by mc.yandex.co.il mc.yandex.com mc.yandex.com.am mc.yandex.com.ge mc.yandex.com.tr mc.yandex.ee mc.yandex.fr mc.yandex.kg mc.yandex.kz mc.yandex.lt mc.yandex.lv mc.yandex.md mc.yandex.ru mc.yandex.tj mc.yandex.tm mc.yandex.ua mc.yandex.uz mc.webvisor.com mc.webvisor.org mc.admetrica.ru yandexmetrica.com:* http://127.0.0.1:30102 http://127.0.0.1:29009 'self' 'unsafe-inline' api.passport.yandex.com mail.yandex.com https://pdd.yandex.ru:* https://pdd.yandex.com:* api-stable.dst.yandex.ru cloud-api.yandex.ru s3.mds.yandex.net https://360-marketing-specials-public.s3.yandex.net ad.adriver.ru content.adriver.ru ev.adriver.ru yastatic.net https://*.static-dev.mail.yandex.net/s3/psf/; frame-src yastatic.net https://*.static-dev.mail.yandex.net/s3/psf/ 'self' 'unsafe-inline' blob: mc.yandex.ru forms.yandex.ru frontend.vh.yandex.ru runtime.strm.yandex.ru runtime.video.cloud.yandex.net www.youtube.com ad.adriver.ru content.adriver.ru ev.adriver.ru yandex.com trust.yandex.com calendar.yandex.ru; child-src 'self' blob: mc.yandex.ru; base-uri 'self'; frame-ancestors 'self' https://*.webvisor.com https://metrika.yandex.com https://metrika.yandex.ru http://ad.adriver.ru https://content.adriver.ru https://ev.adriver.ru https://*.mail.yandex.com https://mail.yandex.com https://disk.yandex.com https://*.disk.yandex.com https://*.disk.dsp.yandex.com https://*.disk.dst.yandex.com https://*.disk-dev.dsd.yandex.com https://*.regtests.dsp.yandex.com https://disk.dst.yandex.com https://disk.dsp.yandex.com https://tavern.mail.yandex.com https://tavern-prestable.mail.yandex.com https://tavern-testing.mail.yandex.com https://*.tavern-dev.mail.yandex.com https://*.taverndemo-dev.mail.yandex.com https://*.qa.tavern.yandex.com https://distribution.yandex.com https://*.distribution.yandex.com https://distribution-test.yandex.com https://*.distribution-test.yandex.com ; report-uri https://csp.yandex.net/csp?from=tuning&project=tuning&yandex_login=&yandexuid=1665398901743899596; |
Content-Type | text/html; charset=utf-8 |
Date | Sun, 06 Apr 2025 00:33:16 GMT |
Vary | Accept-Encoding |
Cache-Control | max-age=0, must-revalidate, proxy-revalidate, no-cache, no-store, private |
Expires | Thu, 01 Jan 1970 00:00:01 GMT |
Pragma | no-cache |
By using SecurityHeaders.info, you can quickly identify missing or misconfigured headers and take steps to secure your website, improving both security and user confidence.
This tool is widely used by developers, security professionals, and organizations to ensure their websites adhere to best practices in web security.
We also have another analytic tool that is used for identifying popularity metrics, general information about the business, finding similar products and competitors, and much more.
Watch it now at TrustRadar