payoff.com | Analytics by SecurityHeaders

HTTP Headers report for payoff.com

Header Name Header Data
HTTP status code 200
Server cloudflare
Vary Accept-Encoding
X-Frame-Options DENY
Content-Type text/html; charset=utf-8
X-Cookie __cf_bm=TclONZt35Jh_4NDfMQMojIe7FjWjppbwyebjkjL1Ia0-1743885218-1.0.1.1-EnXjA5OWZ1kvnAJt0teNbXd7HVZGMGApcctU1Y7aOtaWXIpvRnwIblbo1VTx10GQO1jdCv8Aw3DH8ax3AJHUu6m5SI41tSXRsWKMnyQ4eRc
Cache-Control s-maxage=86400, stale-while-revalidate
Samesite lax
X-Xss-Protection 1; mode=block
Referrer-Policy same-origin
X-Powered-By Next.js
Date Sat, 05 Apr 2025 20:33:39 GMT
P3p CP="This is not a P3P policy! See https://www.payoff.com/legal/privacy-policy/"
X-Dns-Prefetch-Control on
X-Cache Miss from cloudfront
Cf-Cache-Status DYNAMIC
X-Content-Type-Options nosniff
Connection keep-alive
X-Request-Id aefe0d1924932a3c32ad36116f918df0
Strict-Transport-Security max-age=31536000; includeSubDomains; preload
Cf-Ray 92bbd25a38241ca2-AMS
Set-Cookie AWSALB=OUZdmyej3ZfOdUPlXs+A818DPV/WQUkzIBd9hjECHrvhBs7mJC+LfA4W8Ta5l7EXwKB7y3w53LbQwsNk9z2P0s4yvOgn+TrEAKDYXO/QrlOvhg7YRiDi4pr1oamX; Expires=Sat, 12 Apr 2025 20:33:39 GMT; Path=/
X-Nextjs-Cache HIT
X-Uidset pvid=D003E00AA393F1670D00586D024B050C
Content-Security-Policy default-src 'unsafe-inline' 'unsafe-eval' data: blob: wss://*.happymoney.com wss://*.usw2.pure.cloud *.happymoney.com https://happymoney.com https://*.cloudflare.com https://cdn.siftscience.com https://*.digify.com https://*.readme.io https://cdn.plaid.com https://*.googletagmanager.com https://*.googlesyndication.com https://*.google.com https://*.google-analytics.com https://*.googleapis.com https://*.doubleclick.net https://*.googleadservices.com https://fonts.gstatic.com https://cdn.segment.com https://*.segment.io https://*.livechatinc.com https://*.fullstory.com https://*.payoff.com https://stats.g.doubleclick.net https://unpkg.com https://*.ingest.sentry.io https://js.live.net https://use.typekit.net https://sjrtp2-cdn.marketo.com https://munchkin.marketo.net https://script.crazyegg.com https://bat.bing.com https://api.instagram.com https://connect.facebook.net https://*.launchdarkly.com https://*.oktapreview.com https://*.okta.com https://static.cdn.prismic.io https://happymoney-marketing.prismic.io https://www.youtube.com https://*.amazonaws.com https://*.iovation.com https://*.datadoghq.com https://*.browser-intake-datadoghq.com https://point-break.cdn.prismic.io https://images.prismic.io https://cdn.livechat-static.com https://cdn.livechat-files.com https://hexagon-analytics.com https://i.imgur.com https://www.facebook.com https://p.typekit.net https://secure.gravatar.com https://*.usw2.pure.cloud https://snap.licdn.com https://analytics.tiktok.com https://data.adxcel-ec2.com https://*.linkedin.com https://*.linkedin.oribi.io https://*.oktacdn.com https://*.lever.co https://*.ipify.org https://*.twitter.com https://*.ads-twitter.com https://*.pangle-ads.com https://t.co https://*.citadelid.com https://*.truv.com https://happymoney.gw-dv.vip https://happymoney.gw-dv.io https://happymoney.gw-dv.xyz https://happymoney.cdn-gw-dv.vip https://52.42.183.115 https://happymoney.ck123.io https://cdn.mxpnl.com https://*.oscilar.com https://ssl.kaptcha.com; frame-ancestors 'self'
Via 1.1 52bf0b7935ffde0b5e26a7e27e5fe4ce.cloudfront.net (CloudFront)
X-Amz-Cf-Pop AMS1-P3
X-Amz-Cf-Id VWm6VZ7EyPOLWTVR3M9g9E02qdrZHWmPszOafwMbNugN2kD-lN_vmw==

About the tool

By using SecurityHeaders.info, you can quickly identify missing or misconfigured headers and take steps to secure your website, improving both security and user confidence.

This tool is widely used by developers, security professionals, and organizations to ensure their websites adhere to best practices in web security.

We also have another analytic tool that is used for identifying popularity metrics, general information about the business, finding similar products and competitors, and much more.

Watch it now at TrustRadar