Header Name | Header Data |
---|---|
HTTP status code | 200 |
X-Content-Type-Options | nosniff |
X-Fd-Int-Roxy-Purgeid | 0 |
X-Cache | PRIVATE_NOSTORE |
Date | Wed, 16 Apr 2025 19:35:23 GMT |
Content-Type | text/html; charset=utf-8 |
Connection | keep-alive |
Pragma | no-cache |
Strict-Transport-Security | max-age=31536000; includeSubDomains |
X-Permitted-Cross-Domain-Policies | none |
Vary | Accept-Encoding |
Set-Cookie | INGRESSCOOKIE=1744832124.24.8884.864974|5643f8a78b9c02cb9e0ad06b093fbb31; Path=/; Secure; HttpOnly |
Cache-Control | no-cache, no-store |
Referrer-Policy | no-referrer-when-downgrade |
X-Azure-Ref | 20250416T193523Z-r175cd98c7cx5v8phC1DUSuhtc00000002y000000000a8fa |
Expires | -1 |
X-Frame-Options | SAMEORIGIN |
Content-Security-Policy | default-src 'self' 'unsafe-inline' 'unsafe-eval' blob: *.fticonsulting.com *.brightcovecdn.com *.boltdns.net *.media.brightcove.com *.llnw.net *.llnwd.net *.akafms.net *.akamaihd.net *.cf.brightcove.com graph.instagram.com *.ceros.com code.jquery.com www.google.com static.cloud.coveo.com cdn.linkedin.oribi.io script.crazyegg.com z.moatads.com consent.cookiebot.com edge.api.brightcove.com oauth.brightcove.com cms.api.brightcove.com vjs.zencdn.net consentcdn.cookiebot.com players.brightcove.net www.googletagmanager.com sjs.bizographics.com siteimproveanalytics.com static.addtoany.com stats.addtoany.com vidassets.terminus.services www.googleadservices.com googleads.g.doubleclick.net *.demandbase.com *.company-target.com snap.licdn.com www.google-analytics.com *.google-analytics.com *.analytics.google.com www.gstatic.com stats.g.doubleclick.net api.company-target.com maps.googleapis.com graphql.contentful.com images.ctfassets.net videos.ctfassets.net *.n.dps.sh *.onetrust.com; frame-ancestors 'self' players.brightcove.net bid.g.doubleclick.net consentcdn.cookiebot.com graphql.contentful.com images.ctfassets.net videos.ctfassets.net *.n.dps.sh *.onetrust.com; font-src 'self' 'unsafe-inline' data: app.marker.io edge.marker.io fonts.googleapis.com fonts.gstatic.com graphql.contentful.com images.ctfassets.net videos.ctfassets.net *.n.dps.sh *.onetrust.com; img-src 'self' 'unsafe-inline' data: media.marker.io app.marker.io edge.marker.io players.brightcove.net *.boltdns.net *.akamaihd.net *.cdninstagram.com *.fticonsulting.com px.ads.linkedin.com metrics.brightcove.com 63904.global.siteimproveanalytics.io p.adsymptotic.com vidassets.terminus.services www.google.com www.google.com.ec match.prod.bidr.io id.rlcdn.com www.google-analytics.com *.google-analytics.com *.analytics.google.com segments.company-target.com www.linkedin.com match.adsrvr.org maps.gstatic.com maps.googleapis.com www.googletagmanager.com ml.globenewswire.com wec-assets.terminus.services googleads.g.doubleclick.net wec-assets-api.terminus.services graphql.contentful.com images.ctfassets.net videos.ctfassets.net *.n.dps.sh *.onetrust.com; style-src 'self' 'unsafe-inline' fonts.googleapis.com static.cloud.coveo.com graphql.contentful.com images.ctfassets.net videos.ctfassets.net *.n.dps.sh *.onetrust.com players.brightcove.net; child-src 'self' 'unsafe-inline' blob: app.marker.io *.ceros.com *.company-target.com consentcdn.cookiebot.com players.brightcove.net www.google.com static.addtoany.com bid.g.doubleclick.net graphql.contentful.com images.ctfassets.net videos.ctfassets.net *.n.dps.sh *.onetrust.com |
X-Xss-Protection | 1; mode=block |
By using SecurityHeaders.info, you can quickly identify missing or misconfigured headers and take steps to secure your website, improving both security and user confidence.
This tool is widely used by developers, security professionals, and organizations to ensure their websites adhere to best practices in web security.
We also have another analytic tool that is used for identifying popularity metrics, general information about the business, finding similar products and competitors, and much more.
Watch it now at TrustRadar