qm.qld.gov.au | Analytics by SecurityHeaders

HTTP Headers report for qm.qld.gov.au

Header Name Header Data
HTTP status code 200
Cache-Control private, no-cache, no-store, max-age=0, must-revalidate
Strict-Transport-Security max-age=63072000; includeSubDomains; preload
X-Frame-Options SAMEORIGIN
X-Powered-By Next.js
X-Vercel-Id fra1::syd1::khz2k-1746912525717-42b759b71aca
Set-Cookie qm-website#lang=en; path=/; secure; SameSite=None
X-Xss-Protection 1; mode=block
Content-Security-Policy default-src 'self' 'unsafe-inline' 'unsafe-eval' museum.qld.gov.au *.museum.qld.gov.au mc-24937cab-d83c-449f-a961-1808-cd.azurewebsites.net mc-24937cab-d83c-449f-a961-1808-cm.azurewebsites.net mc-24937cab-d83c-449f-a961-1808-cd-staging.azurewebsites.net mc-24937cab-d83c-449f-a961-1808-cm-staging.azurewebsites.net *.raiselysite.com *.raisely.com *.monsido.com *.paperturn-view.com qm.qld.gov.au *.qm.qld.gov.au vercel.live *.vercel.app *.azurewebsites.net *.littlehinges.com.au *.crazyegg.com pagecorrect.monsido.com stats.g.doubleclick.net *.raisely.com *.raiselysite.com sketchfab.com www.paperturn-view.com www.gstatic.com apps.sitecore.net connect.facebook.net www.facebook.com *.google.com www.googletagmanager.com www.google-analytics.com googleads.g.doubleclick.net *.sharethis.com *.apple.com rss.app www.youtube.com *.jotform.com *.unpkg.com sketchfab-prod-media.s3.amazonaws.com analytics.tiktok.com www.googleadservices.com td.doubleclick.net www.google.com.au; worker-src blob:; script-src 'self' 'unsafe-inline' 'unsafe-eval' museum.qld.gov.au *.museum.qld.gov.au mc-24937cab-d83c-449f-a961-1808-cd.azurewebsites.net mc-24937cab-d83c-449f-a961-1808-cm.azurewebsites.net mc-24937cab-d83c-449f-a961-1808-cd-staging.azurewebsites.net mc-24937cab-d83c-449f-a961-1808-cm-staging.azurewebsites.net *.raiselysite.com *.raisely.com *.monsido.com *.paperturn-view.com *.qm.qld.gov.au qm.qld.gov.au vercel.live *.vercel.app *.azurewebsites.net cdn-au.clickdimensions.com analytics-au.clickdimensions.com *.littlehinges.com.au app-script.monsido.com pagecorrect.monsido.com tracking.monsido.com script.crazyegg.com www.googletagmanager.com www.google-analytics.com connect.facebook.net https://www.google.com https://www.gstatic.com www.googleadservices.com analytics.tiktok.com; img-src 'self' museum.qld.gov.au *.museum.qld.gov.au mc-24937cab-d83c-449f-a961-1808-cd.azurewebsites.net mc-24937cab-d83c-449f-a961-1808-cm.azurewebsites.net mc-24937cab-d83c-449f-a961-1808-cd-staging.azurewebsites.net mc-24937cab-d83c-449f-a961-1808-cm-staging.azurewebsites.net *.raiselysite.com *.raisely.com *.monsido.com *.paperturn-view.com qm.qld.gov.au *.qm.qld.gov.au vercel.live *.vercel.app cdn-au.clickdimensions.com *.googleadservices.com www.facebook.com *.googletagmanager.com googleads.g.doubleclick.net connect.facebook.net *.google.com.au *.google.com *.google-analytics.com tracking.monsido.com db6.auroracloud.com.au data:; style-src 'self' 'unsafe-inline' museum.qld.gov.au *.museum.qld.gov.au mc-24937cab-d83c-449f-a961-1808-cd.azurewebsites.net mc-24937cab-d83c-449f-a961-1808-cm.azurewebsites.net mc-24937cab-d83c-449f-a961-1808-cd-staging.azurewebsites.net mc-24937cab-d83c-449f-a961-1808-cm-staging.azurewebsites.net *.raiselysite.com *.raisely.com *.monsido.com *.paperturn-view.com qm.qld.gov.au *.qm.qld.gov.au vercel.live *.vercel.app cdn-au.clickdimensions.com pagecorrect.monsido.com fonts.googleapis.com; font-src 'self' 'unsafe-inline' museum.qld.gov.au *.museum.qld.gov.au mc-24937cab-d83c-449f-a961-1808-cd.azurewebsites.net mc-24937cab-d83c-449f-a961-1808-cm.azurewebsites.net mc-24937cab-d83c-449f-a961-1808-cd-staging.azurewebsites.net mc-24937cab-d83c-449f-a961-1808-cm-staging.azurewebsites.net *.raiselysite.com *.raisely.com *.monsido.com *.paperturn-view.com qm.qld.gov.au vercel.live *.vercel.app cdn-au.clickdimensions.com *.littlehinges.com.au pagecorrect.monsido.com sketchfab.com www.gstatic.com connect.facebook.net www.facebook.com *.google.com fonts.gstatic.com googleads.g.doubleclick.net; upgrade-insecure-requests; block-all-mixed-content;
Date Sat, 10 May 2025 21:28:46 GMT
Etag W/"eb8t172mkn43f3"
Server Vercel
X-Matched-Path /en/[[...path]]
X-Vercel-Cache MISS
Age 0
Content-Type text/html; charset=utf-8
X-Content-Type-Options nosniff

About the tool

By using SecurityHeaders.info, you can quickly identify missing or misconfigured headers and take steps to secure your website, improving both security and user confidence.

This tool is widely used by developers, security professionals, and organizations to ensure their websites adhere to best practices in web security.

We also have another analytic tool that is used for identifying popularity metrics, general information about the business, finding similar products and competitors, and much more.

Watch it now at TrustRadar