Header Name | Header Data |
---|---|
HTTP status code | 200 |
Connection | keep-alive |
X-Frame-Options | sameorigin |
X-Ratelimit-Bucket | global-limit |
X-Ratelimit-Limit | 25 |
X-Ratelimit-Reset | 1745214953 |
X-Request-Id | a402261f30a7934a94807f20cd0d8e04 |
Vary | Accept-Encoding |
X-Nonce | 78GpMj_WuQdA-qggFYAq9Q |
X-Ratelimit-Remaining | 24 |
Date | Mon, 21 Apr 2025 05:55:43 GMT |
Content-Type | text/html; charset=utf-8 |
Etag | "15yujohgvdh7gb3" |
Strict-Transport-Security | max-age=15552000; includeSubDomains |
X-Xss-Protection | 1; mode=block |
Cache-Control | private, no-cache, no-store, max-age=0, must-revalidate |
Content-Security-Policy | default-src 'self' https://assets.getmyboat.com; connect-src 'self' https://assets.getmyboat.com img.getmyboat.com getmyboat-user-images1.imgix.net wss://www.getmyboat.com gtm.getmyboat.com o33203.ingest.sentry.io www.google-analytics.com stats.g.doubleclick.net https://*.google.com https://*.google.ca https://*.google.co.in https://*.google.co.uk https://*.google.com.mx https://*.google.de https://*.google.com.au https://*.google.it https://*.google.nl https://*.google.com.tr https://*.google.com.ph https://*.google.es https://*.google.gr https://*.google.hr https://*.google.fr https://*.google.com.pr https://*.google.pt https://*.google.co.il https://*.google.com.cy https://*.google.ie https://*.google.ae https://*.google.ch https://*.google.co.id https://*.google.co.za https://*.google.se https://*.google.com.sg https://*.google.bs https://*.google.com.co https://*.google.be https://*.google.pl https://*.googleapis.com https://*.gstatic.com translate.googleapis.com getmyboat-user-images2.imgix.net graph.facebook.com www.facebook.com api.mapbox.com *.tiles.mapbox.com events.mapbox.com getmyboat-uploads-temp-prod.s3.us-east-1.amazonaws.com getmyboat-uploads-processed.s3.us-east-1.amazonaws.com ct.pinterest.com *.clarity.ms *.bing.com *.amazon-adsystem.com *.paa-reporting-advertising.amazon plausible.io; script-src 'self' 'nonce-78GpMj_WuQdA-qggFYAq9Q' www.getmyboat.com https://assets.getmyboat.com gtm.getmyboat.com www.google-analytics.com stats.g.doubleclick.net www.googletagmanager.com www.googleadservices.com googleads.g.doubleclick.net www.google.com www.gstatic.com https://*.googleapis.com translate.googleapis.com connect.facebook.net s.pinimg.com *.clarity.ms *.bing.com *.amazon-adsystem.com plausible.io; style-src 'self' 'unsafe-inline' https://assets.getmyboat.com https://fonts.googleapis.com translate.googleapis.com; img-src 'self' data: https://assets.getmyboat.com img.getmyboat.com getmyboat-user-images1.imgix.net cms-media.getmyboat.com www.google-analytics.com stats.g.doubleclick.net www.gstatic.com www.googletagmanager.com googleads.g.doubleclick.net https://*.google.com https://*.google.ca https://*.google.co.in https://*.google.co.uk https://*.google.com.mx https://*.google.de https://*.google.com.au https://*.google.it https://*.google.nl https://*.google.com.tr https://*.google.com.ph https://*.google.es https://*.google.gr https://*.google.hr https://*.google.fr https://*.google.com.pr https://*.google.pt https://*.google.co.il https://*.google.com.cy https://*.google.ie https://*.google.ae https://*.google.ch https://*.google.co.id https://*.google.co.za https://*.google.se https://*.google.com.sg https://*.google.bs https://*.google.com.co https://*.google.be https://*.google.pl https://*.googleapis.com https://*.gstatic.com translate.googleapis.com getmyboat-user-images2.imgix.net www.facebook.com web.facebook.com blob: api.mapbox.com getmyboat-uploads-processed.s3.amazonaws.com getmyboat-uploads-processed.s3.us-east-1.amazonaws.com ct.pinterest.com *.clarity.ms c.bing.com *.bing.com arttrk.com; font-src 'self' https://assets.getmyboat.com data: https://fonts.gstatic.com; worker-src 'self' https://assets.getmyboat.com blob:; child-src 'self' https://assets.getmyboat.com graph.facebook.com blob:; frame-src 'self' https://assets.getmyboat.com bid.g.doubleclick.net tpc.googlesyndication.com www.google.com https://www.youtube.com/ *.facebook.com ct.pinterest.com *.amazon-adsystem.com; base-uri 'none'; object-src 'none'; block-all-mixed-content; frame-ancestors 'self'; |
Set-Cookie | preferred_currency=EUR; Path=/; Max-Age=31536000 |
X-Content-Type-Options | nosniff |
X-Download-Options | noopen |
By using SecurityHeaders.info, you can quickly identify missing or misconfigured headers and take steps to secure your website, improving both security and user confidence.
This tool is widely used by developers, security professionals, and organizations to ensure their websites adhere to best practices in web security.
We also have another analytic tool that is used for identifying popularity metrics, general information about the business, finding similar products and competitors, and much more.
Watch it now at TrustRadar