mfat.govt.nz | Analytics by SecurityHeaders

HTTP Headers report for mfat.govt.nz

Header Name Header Data
HTTP status code 200
Content-Type text/html; charset=utf-8
X-Xss-Protection 1; mode=block
Cache-Control no-cache, must-revalidate
Set-Cookie FluentLocale=en_NZ; expires=Wed, 16 Jul 2025 18:01:39 GMT; Max-Age=7776000; path=/; secure; HttpOnly; SameSite=Lax
X-Varnish 317528084
Age 0
Accept-Ranges bytes
Etag "2110667c1a434bece64c7ff2a556f152-gzip"
X-Content-Type-Options nosniff
Vary Accept-Encoding
Content-Security-Policy-Report-Only default-src 'none'; base-uri 'self'; child-src 'self' *.youtube-nocookie.com *.twitter.com *.gstatic.com *.googleapis.com *.googletagmanager.com 3f5l8ze0o4j2m.cloudfront.net *.youtube.com *.youtube-no-cookie.com *.ytimg.com *.google.com www.google.com https://www.facebook.com https://staticxx.facebook.com; connect-src 'self' *.twimg.com *.twitter.com *.gstatic.com *.googleapis.com https://www.facebook.com/tr; frame-ancestors 'self'; font-src *.twimg.com *.twitter.com *.gstatic.com *.googleapis.com fonts.gstatic.com data: 'self'; form-action 'self' *.twitter.com https://login.microsoftonline.com https://connect.facebook.com; img-src 'self' *.twimg.com *.twitter.com *.gstatic.com *.googleapis.com *.google-analytics.com *.googletagmanager.com d3f5l8ze0o4j2m.cloudfront.net *.ytimg.com data: https://www.facebook.com; manifest-src 'self'; media-src 'none'; object-src 'none'; script-src 'self' 'unsafe-inline' *.twimg.com *.twitter.com *.googleapis.com *.jquery.com *.google.com *.google-analytics.com *.googletagmanager.com 'unsafe-eval' d3f5l8ze0o4j2m.cloudfront.net www.gstatic.com https://connect.facebook.net; style-src 'self' *.twimg.com *.twitter.com *.gstatic.com *.googleapis.com fonts.googleapis.com 'unsafe-inline';
Date Thu, 17 Apr 2025 18:01:41 GMT
Connection keep-alive
Strict-Transport-Security max-age=31536000; includeSubDomains; preload
X-Frame-Options SAMEORIGIN
Referrer-Policy same-origin

About the tool

By using SecurityHeaders.info, you can quickly identify missing or misconfigured headers and take steps to secure your website, improving both security and user confidence.

This tool is widely used by developers, security professionals, and organizations to ensure their websites adhere to best practices in web security.

We also have another analytic tool that is used for identifying popularity metrics, general information about the business, finding similar products and competitors, and much more.

Watch it now at TrustRadar