Header Name | Header Data |
---|---|
HTTP status code | 200 |
Vary | Accept-Encoding |
Expires | Sun, 06 Apr 2025 13:17:27 GMT |
Last-Modified | Tue, 01 Apr 2025 17:28:28 GMT |
Referrer-Policy | strict-origin-when-cross-origin |
X-Content-Type-Options | nosniff |
Strict-Transport-Security | max-age=31536000 ; includeSubDomains ; preload |
X-Xss-Protection | 1; mode=block |
Date | Sun, 06 Apr 2025 13:16:40 GMT |
X-Frame-Options | SAMEORIGIN |
Cache-Control | max-age=47 |
Connection | keep-alive |
Pragma | no-cache |
Hsbc-Classification | PUBLIC |
X-Robots-Tag | index, follow |
Accept-Ch | Sec-CH-UA-Full-Version-List,Sec-CH-UA-Platform-Version,Sec-CH-UA-Arch,Sec-CH-UA-Model,Sec-CH-UA-Bitness |
Content-Type | text/html; charset=utf-8 |
Etag | "lr9ACJlGJIaABdPJKUd7Wg==" |
Content-Security-Policy | default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' app.contentsquare.com my.tealiumiq.com t.contentsquare.net q-eu1.az.contentsquare.net k-eu1.az.contentsquare.net q-aeu1.contentsquare.net k-aeu1.contentsquare.net c.az.contentsquare.net r.contentsquare.net c.contentsquare.net l.contentsquare.net https://googleads.g.doubleclick.net https://www.googleadservices.com googletagmanager.com *.googletagmanager.com collect.tealiumiq.com cm.everesttech.net hsbcbankcommon.demdex.net snap.licdn.com code.highcharts.com http://pbs.twimg.com irs.tools.investis.com maps.googleapis.com s.ytimg.com http://i3.ytimg.com www.youtube.com blob: www.recaptcha.net www.gstatic.com brightcove.net *.brightcove.net brightcove.com *.brightcove.com tags.tiqcdn.com tags.tiqcdn.cn facebook.com connect.facebook.net ads.linkedin.com www.linkedin.com dc.ads.linkedin.com twitter.com analytics.twitter.com static.ads-twitter.com adsymptotic.com hsbcglobalcommon.tt.omtrdc.net vjs.zencdn.net pws.internal.hsbc *.pws.internal.hsbc hsbc.com; img-src 'self' https://*.fls.doubleclick.net adservice.google.com ad.doubleclick.net my.tealiumiq.com dpm.demdex.net t.contentsquare.net q-eu1.az.contentsquare.net k-eu1.az.contentsquare.net q-aeu1.contentsquare.net k-aeu1.contentsquare.net c.az.contentsquare.net r.contentsquare.net c.contentsquare.net l.contentsquare.net boltdns.net media.licdn.com *.boltdns.net collect.tealiumiq.com cm.everesttech.net hsbcbankcommon.demdex.net https://www.google.com https://www.google.co.uk https://www.google.co.in https://www.google.com.hk https://www.google.com.sg px.ads.linkedin.com pxl.yoptima.com pixel.quantserve.com i.ytimg.com http://i3.ytimg.com data: http://pbs.twimg.com sprcdn-assets.sprinklr.com media-exp1.licdn.com dms.licdn.com brightcove.net *.brightcove.net brightcove.com *.brightcove.com tags.tiqcdn.com twitter.com analytics.twitter.com static.ads-twitter.com adsymptotic.com tags.tiqcdn.cn facebook.com connect.facebook.net ads.linkedin.com www.linkedin.com dc.ads.linkedin.com hsbcglobalcommon.tt.omtrdc.net hsbcglobalcommon.sc.omtrdc.net akamaihd.net *.akamaihd.net maps.gstatic.com maps.googleapis.com blob: pws.internal.hsbc *.pws.internal.hsbc hsbc.com; connect-src 'self' pagead2.googlesyndication.com cdn.linkedin.oribi.io t.contentsquare.net q-eu1.az.contentsquare.net k-eu1.az.contentsquare.net q-aeu1.contentsquare.net k-aeu1.contentsquare.net c.az.contentsquare.net r.contentsquare.net c.contentsquare.net l.contentsquare.net manifest.prod.boltdns.net collect.tealiumiq.com cm.everesttech.net hsbcbankcommon.demdex.net cf.brightcove.com *.cf.brightcove.com ingestion-upload-production.s3.amazonaws.com bcvp0rtal.com *.bcvp0rtal.com gallerysites.net *.gallerysites.net vjs.zencdn.net *.vjs.zencdn.net hlstoken-a.akamaihd.net *.hlstoken-a.akamaihd.net media.brightcove.com *.media.brightcove.com cloudfront.net *.cloudfront.net analytics.edgekey.net *.analytics.edgekey.net akafms.net *.akafms.net llnwd.net *.llnwd.net llnw.net *.llnw.net brightcove.vo.llnwd.net *.brightcove.vo.llnwd.net uds.ak.o.brightcove.com *.uds.ak.o.brightcove.com hls.ak.o.brightcove.com *.hls.ak.o.brightcove.com players.brightcove.net *.players.brightcove.net o.brightcove.com *.o.brightcove.com bcovlive-a.akamaihd.net *.bcovlive-a.akamaihd.net sep.bcovlive.io *.sep.bcovlive.io bcovlive.io *.bcovlive.io api.bcovlive.io *.api.bcovlive.io api.brightcove.com *.api.brightcove.com bcove.video *.bcove.video brightcove.net *.brightcove.net *.brightcovecdn.com boltdns.net *.boltdns.net hsbcglobalcommon.sc.omtrdc.net dpm.demdex.net bcsecure01-a.akamaihd.net *.akamaihd.net hsbcglobalcommon.tt.omtrdc.net brightcove.com *.brightcove.com www.youtube.com akamai.tiqcdn.com; font-src 'self' data:; form-action 'self'; base-uri 'self'; style-src 'self' 'unsafe-inline' players.brightcove.net; frame-src 'self' https://*.fls.doubleclick.net https://td.doubleclick.net csxd.hsbc.com *.demdex.net youtube-nocookie.com *.youtube-nocookie.com *.recaptcha.net recaptcha.net players.brightcove.net www.youtube.com www.google.com irs.tools.investis.com; media-src 'self' blob: akafms.net *.akafms.net llnwd.net *.llnwd.net llnw.net *.llnw.net media.brightcove.com *.media.brightcove.com brightcovecdn.com *.brightcovecdn.com boltdns.net *.boltdns.net video.twimg.com dms.licdn.com pws.internal.hsbc *.pws.internal.hsbc hsbc.com hsbcbankcommon.demdex.net brightcove.com *.brightcove.com *.akamaihd.net t.contentsquare.net q-eu1.az.contentsquare.net k-eu1.az.contentsquare.net q-aeu1.contentsquare.net k-aeu1.contentsquare.net c.az.contentsquare.net r.contentsquare.net c.contentsquare.net l.contentsquare.net; |
By using SecurityHeaders.info, you can quickly identify missing or misconfigured headers and take steps to secure your website, improving both security and user confidence.
This tool is widely used by developers, security professionals, and organizations to ensure their websites adhere to best practices in web security.
We also have another analytic tool that is used for identifying popularity metrics, general information about the business, finding similar products and competitors, and much more.
Watch it now at TrustRadar