Header Name | Header Data |
---|---|
HTTP status code | 200 |
X-Request-Id | v-12c3d1b0-1e33-11f0-ad82-df5d386a533a |
Accept-Ranges | bytes |
Date | Mon, 21 Apr 2025 03:28:13 GMT |
Content-Type | text/html; charset=UTF-8 |
Expires | Sun, 19 Nov 1978 05:00:00 GMT |
Vary | Cookie,Origin,Accept-Encoding |
Content-Language | nl |
Access-Control-Allow-Origin | * |
X-Frame-Options | ALLOW-FROM *.mobistar.be *.orange.be *.optimizely.com mobile.kbc-group.com mobileyoungsterapp.kbc-group.com kbctouch.kbc.be cbctouch.cbc.be touch.kbcbrussels.be |
Connection | keep-alive |
Cache-Control | max-age=31536000, public |
X-Content-Type-Options | nosniff |
X-Cache-Hits | 4390 |
X-Ah-Environment | prod |
Age | 19576 |
Via | varnish |
X-Cache | HIT |
Referrer-Policy | strict-origin-when-cross-origin |
Strict-Transport-Security | max-age=31536000; includeSubDomains |
X-Xss-Protection | 1; mode=block |
Etag | "1745186515-gzip" |
X-Cdn | Imperva |
X-Iinfo | 2-6362459-6362460 SNNN RT(1745206093396 89) q(0 0 0 -1) r(0 1) U24 |
Content-Security-Policy | default-src 'self' *.orange.be *.google.es *.abtasty.com *.fontawesome.com *.typekit.net *.digitalchannels.technology cdn.jsdelivr.net *.cookielaw.org *.googletagmanager.com *.optimizegoogle.com *.optimize-google.com *.googleanalytics.com *.google-analytics.com *.newrelic.com *.onetrust.com *.hotjar.com *.adbutter.net *.adnxs.com *.doubleclick.net *.amazon-adsystem.com brand-messenger.app.khoros.com *.khoros.com ssl://brandmessenger-ws.euw1.khoros.com:8883 proactive-chat-server-eu.prod.aws.lcloud.com messaging-auth-eu-west-1.prod.aws.lcloud.com; script-src blob: 'self' 'unsafe-inline' 'unsafe-eval' * https://optimize.google.com https://www.googleanalytics.com https://www.google-analytics.com https://www.googleoptimize.com https://googleads.g.doubleclick.net https://script.hotjar.com https://connect.facebook.net https://www.googleadservices.com http//www.googleadservices.com https://static.hotjar.com https://trk.adbutter.net https://accounts.google.com https://www.googleanalytics.com https://www.googleoptimize.com *.customersaas.com t.contentsquare.net contentsquare.com *.emsecure.net *.customersaas.com *.orange.be *.netdna-ssl.com blob: *.abtasty.com *.googleapis.com https://assets.pinterest.com https://widgets.pinterest.com; object-src 'self' *.mobistar.be *.orange.be *.netdna-ssl.com; style-src 'unsafe-inline' 'self' https://optimize.google.com https://fonts.googleapis.com *.mobistar.be *.cloudfront.net *.customersaas.com *.orange.be *.netdna-ssl.com cdnjs.cloudflare.com *.gstatic.com *.abtasty.com *.googleapis.com messaging-khoros.app.khoros.com cdn.jsdelivr.net *.typekit.net *.googletagmanager.com; img-src * blob: https://optimize.google.com *.orange.be https://www.facebook.com https://www.google.com https://www.google.es https://static.hotjar.com *.fls.doubleclick.net https://brand-messenger.app.khoros.com *.adnxs.com https://p1.zemanta.com https://aax-eu.amazon-adsystem.com https://www.google-analytics.com *.googletagmanager.com data: *.abtasty.com *.amazonaws.com *.cloudfront.net *.contentsquare.net https://i.pinimg.com https://log.pinterest.com; media-src 'self' data: *.mobistar.be *.orange.be *.netdna-ssl.com brand-messenger.app.khoros.com https://v.pinimg.com; frame-src 'self' https://optimize.google.com * emsecure.net *.orange.be https://assets.pinterest.com; font-src 'self' https://fonts.gstatic.com *.mobistar.be *.customersaas.com *.orange.be cdn.livechatinc.com themes.googleusercontent.com *.netdna-ssl.com blob: data: *.googleapis.com *.gstatic.com *.abtasty.com brand-messenger.app.khoros.com messaging-khoros.app.khoros.com *.typekit.net *.fontawesome.com; connect-src 'self' *.googlesyndication.com *.gstatic.com w998baawd3-dsn.algolia.net uq5v1rcrhz-dsn.algolia.net *.algolianet.com insights.algolia.io *.cloudfront.net *.tealiumiq.com *.usabilla.com *.emsecure.net *.customersaas.com wss://*.khoros.com wss://*.khorostech.com *.eshop.orange.be *.orange.be *.digitalchannels.technology *.mousestats.com secure.comparecycle.com *.abtasty.com *.contentsquare.net *.smooch.io *.slgnt.eu *.google-analytics.com *.prod.aws.lcloud.com *.typekit.net cdn.jsdelivr.net *.nr-data.net cdnjs.cloudflare.com *.google.com *.google.es *.google.be *.fontawesome.com *.cookielaw.org *.onetrust.com *.hotjar.com *.adbutter.net *.adnxs.com *.doubleclick.net *.newrelic.com wss://*.hotjar.com *.googletagmanager.com *.ipify.org px.ads.linkedin.com *.zemanta.com *.googleadservices.com *.facebook.net *.facebook.com *.hotjar.io *.amazon-adsystem.com browser-update.org *.googleapis.com *.tiqcdn.com *.teads.tv *.pinterest.com *.taboola.com *.clarity.ms *.gsitrix.com *.adensemble.com *.cookieless-data.com bbd-tag.de admaxium.com *.perfectaudiencertg.com *.netdna-ssl.com *.twitter.com *.bing.com *.pinimg.com *.licdn.com https://static.ads-twitter.com https://js.adsrvr.org https://img.netaffiliation.com https://files.qualifio.com *.khoros.com; frame-ancestors 'self' https://mobile.kbc-group.com https://kbctouch.kbc.be https://cbctouch.cbc.be https://touch.kbcbrussels.be https://mobileyoungsterapp.kbc-group.com ; |
Last-Modified | Sun, 20 Apr 2025 22:01:55 GMT |
Server | nginx |
By using SecurityHeaders.info, you can quickly identify missing or misconfigured headers and take steps to secure your website, improving both security and user confidence.
This tool is widely used by developers, security professionals, and organizations to ensure their websites adhere to best practices in web security.
We also have another analytic tool that is used for identifying popularity metrics, general information about the business, finding similar products and competitors, and much more.
Watch it now at TrustRadar