ramboll.com | Analytics by SecurityHeaders

HTTP Headers report for ramboll.com

Header Name Header Data
HTTP status code 200
Referrer-Policy no-referrer, strict-origin-when-cross-origin
X-Azure-Ref 20250413T003128Z-17c6d75d56fxqvkxhC1AMSrxfs00000004f000000000er82
Set-Cookie nonce=695033c8-6c6f-48c1-a5a0-0dcb8dd4d321; Path=/; Secure
X-Content-Type-Options nosniff
X-Nextjs-Cache HIT
Date Sun, 13 Apr 2025 00:31:29 GMT
Content-Type text/html; charset=utf-8
Etag "13ba3ovscbl7iof"
Vary Accept-Encoding
X-Frame-Options DENY
X-Xss-Protection 1; mode=block
X-Dns-Prefetch-Control on
Content-Security-Policy default-src https:; script-src-elem 'self' https://ramboll.piwik.pro/38a88bde-ea4f-48b8-8a99-d2af202b29ef.js https://heatmaps.monsido.com/ https://*.googlesyndication.com https://video.ramboll.com/ https://data.ramboll.com/ https://app-script.monsido.com/ https://stapecdn.com/ https://js.hs-analytics.net *.hs-analytics.net https://bat.bing.com https://bat.bing.net https://bat.bing.com/bat.js https://ramboll.piwik.pro/containers/38a88bde-ea4f-48b8-8a99-d2af202b29ef.js https://ramboll.piwik.pro/containers/container-debugger/scripts.js https://ramboll.piwik.pro/containers/a5869f5d-4073-4da4-8483-ea85261aa481.js https://ramboll.containers.piwik.pro https://ramboll.piwik.pro/containers/ https://ramboll.piwik.pro/containers/container-debugger/templates.cache.js 'unsafe-inline' https://ramboll.piwik.pro/containers/container-debugger/vendor.js *.googletagmanager.com https://js.hubspot.com/web-interactives-embed.js *.hubspot.com https://consent.cookiebot.com/uc.js https://consentcdn.cookiebot.com/consentconfig/ https://consent.cookiebot.com/ https://app.kontent.ai/js-api/custom-element/v1/custom-element.min.js https://*.googleapis.com https://*.gstatic.com *.google.com https://*.ggpht.com *.googleusercontent.com blob: http://js.hsforms.net/forms/v2.js https://ajax.googleapis.com/ajax/libs/jquery/3.5.1/jquery.min.js http://js.hsforms.net/forms/v2.js https://ajax.googleapis.com/ajax/libs/jquery/3.5.1/jquery.min.js https://snap.licdn.com/ https://static.hotjar.com/ https://connect.facebook.net https://js.hs-scripts.com/ https://youraccount.videomarketingplatform.co/ *.doubleclick.net https://*.fls.doubleclick.net https://script.hotjar.com/ https://js.hs-analytics.net/analytics/ https://js.hs-analytics.net.x.85869d700539a049d60a1b709c5d4c3dc584.9270fc4a.id.opendns.com https://js.hs-banner.com https://js.hsleadflows.net https://js.hs-banner.com/integrations.js https://js.hs-analytics.net/analytics/1678953600000/7520151.js https://js.hsleadflows.net/leadflows.js https://script.hotjar.com/modules.b58f4dbb50ff88fc1f15.js https://subscriptions.smartrecruiters.com/widget/v1/sr-job-alerts.js https://www.googleadservices.com/pagead/conversion/ https://www.googleadservices.com/ https://www.googletagmanager.com/gtm.js; script-src 'self' 'strict-dynamic' 'unsafe-inline' 'nonce-695033c8-6c6f-48c1-a5a0-0dcb8dd4d321' https://www.googleadservices.com https://js.hs-analytics.net https://bat.bing.com https://bat.bing.net https://ramboll.piwik.pro/containers/ https://*.googletagmanager.com https://ramboll.piwik.pro/ppms.js *.hubspot.com https://js.hubspot.com https://consent.cookiebot.com https://*.googleapis.com https://*.gstatic.com *.google.com https://*.ggpht.com *.googleusercontent.com https://snap.licdn.com/ https://static.hotjar.com/ https://connect.facebook.net https://js.hs-scripts.com/ https://youraccount.videomarketingplatform.co/ *.doubleclick.net https://*.fls.doubleclick.net blob: 'unsafe-eval' https://www.googletagmanager.com/gtm.js ; style-src 'self' 'unsafe-inline' https://ramboll.piwik.pro/containers/container-debugger/styles.css https://ramboll.piwik.pro/containers/container-debugger/animate.min.css https://ramboll.piwik.pro/containers/ https://ramboll.piwik.pro/containers/container-debugger/icons.css https://fonts.googleapis.com https://ramboll.containers.piwik.pro; connect-src 'self' https://ramboll.piwik.pro https://heatmaps.monsido.com https://video.ramboll.com https://data.ramboll.com https://app-script.monsido.com https://stapecdn.com https://www.google.co.in https://bat.bing.com https://bat.bing.net https://sentryapp.appsupport.frontify.dev/api/51/envelope/ https://content.hotjar.io/ https://metrics.hotjar.io/ wss://ws.hotjar.com/api/v2/client/ https://northeurope-2.in.applicationinsights.azure.com/v2/track https://*.googletagmanager.com https://ramboll.containers.piwik.pro https://ramboll.piwik.pro https://cdn.linkedin.oribi.io https://consentcdn.cookiebot.com https://deliver.kontent.ai/26f8b85f-a743-0128-e3f3-719c3639660e/ https://deliver.kontent.ai/2c6d42b3-af56-014e-57e9-7c6258e60838/ https://deliver.kontent.ai/7c3778f1-714a-0155-9be8-162f4c282b22/ https://preview-deliver.kontent.ai/26f8b85f-a743-0128-e3f3-719c3639660e/ https://deliver.kontent.ai/26f8b85f-a743-0128-e3f3-719c3639660e/ https://deliver.kontent.ai/2c6d42b3-af56-014e-57e9-7c6258e60838/ https://deliver.kontent.ai/7c3778f1-714a-0155-9be8-162f4c282b22/ https://preview-deliver.kontent.ai/2c6d42b3-af56-014e-57e9-7c6258e60838/ https://preview-deliver.kontent.ai/7c3778f1-714a-0155-9be8-162f4c282b22/ https://brandcentral.ramboll.com/ https://api.hubapi.com/forms/v2/forms https://*.googleapis.com *.google.com https://*.gstatic.com https://snap.licdn.com/ https://static.hotjar.com/ https://connect.facebook.net https://js.hs-scripts.com/ https://youraccount.videomarketingplatform.co/ *.doubleclick.net https://*.fls.doubleclick.net data: blob: https://forms.hsforms.com/embed/v3/form/ https://forms.hsforms.com/emailcheck/v1/ https://google.com https://www.microsoft.com/ *.hubspot.com https://js.hubspot.com https://newrelic.com https://*.ramboll.com/ https://www.hotjar.com/ https://soundcloud.com/ https://www.smartrecruiters.com/ https://video.ramboll.com/ https://internalvideo.ramboll.com/ https://www.facebook.com https://www.linkedin.com/ https://*.linkedin.com/ https://forms.hubspot.com/lead-flows-config/v1/config/json https://vc.hotjar.io/sessions/1206552 https://pagead2.googlesyndication.com https://in.hotjar.com/api/v2/client/sites/1206552/visit-data https://customformsapi.rambolltest.com/documentartifact/Content; frame-src 'self' https://www.googletagmanager.com/ https://subscriptions.smartrecruiters.com/ https://www.linkedin.com/ https://*.linkedin.com/ https://consentcdn.cookiebot.com https://brandcentral.ramboll.com/ *.google.com https://forms.hsforms.com/ https://*.ramboll.com/ https://w.soundcloud.com/ https://open.spotify.com/ https://snap.licdn.com/ https://static.hotjar.com/ https://connect.facebook.net https://js.hs-scripts.com/ https://youraccount.videomarketingplatform.co/ *.doubleclick.net https://*.fls.doubleclick.net https://www.facebook.com/ https://*.hs-sites.com/; img-src 'self' https://*.googletagmanager.com https://ramboll.containers.piwik.pro https://ramboll.piwik.pro https: data: https://preview-assets-eu-01.kc-usercontent.com/26f8b85f-a743-0128-e3f3-719c3639660e/ https://deliver.kontent.ai/26f8b85f-a743-0128-e3f3-719c3639660e/ https://deliver.kontent.ai/2c6d42b3-af56-014e-57e9-7c6258e60838/ https://deliver.kontent.ai/7c3778f1-714a-0155-9be8-162f4c282b22/ https://preview-deliver.kontent.ai/2c6d42b3-af56-014e-57e9-7c6258e60838/ https://preview-assets-eu-01.kc-usercontent.com/7c3778f1-714a-0155-9be8-162f4c282b22/ https://*.googleapis.com https://*.gstatic.com *.google.com *.googleusercontent.com *.googletagmanager.com https://pagead2.googlesyndication.com https://snap.licdn.com/ https://static.hotjar.com/ https://connect.facebook.net https://js.hs-scripts.com/ https://youraccount.videomarketingplatform.co/ *.doubleclick.net https://*.fls.doubleclick.net data:; media-src 'self' https: data: https://preview-assets-eu-01.kc-usercontent.com/26f8b85f-a743-0128-e3f3-719c3639660e/ https://deliver.kontent.ai/26f8b85f-a743-0128-e3f3-719c3639660e/ https://deliver.kontent.ai/2c6d42b3-af56-014e-57e9-7c6258e60838/ https://deliver.kontent.ai/7c3778f1-714a-0155-9be8-162f4c282b22/ https://preview-deliver.kontent.ai/2c6d42b3-af56-014e-57e9-7c6258e60838/ https://preview-assets-eu-01.kc-usercontent.com/7c3778f1-714a-0155-9be8-162f4c282b22/ https://snap.licdn.com/ https://static.hotjar.com/ https://connect.facebook.net https://js.hs-scripts.com/ https://youraccount.videomarketingplatform.co/ *.doubleclick.net https://*.fls.doubleclick.net; font-src 'self' https://ramboll.piwik.pro/containers/container-debugger/fonts/bootstrap/glyphicons-halflings-regular.ttf https://ramboll.piwik.pro/containers/container-debugger/fonts https://ramboll.piwik.pro/containers/container-debugger/fonts/7tagicon.woff https://fonts.gstatic.com https://ramboll.containers.piwik.pro; object-src none; block-all-mixed-content; worker-src blob:; frame-ancestors 'self' https://app.kontent.ai; base-uri self;
Connection keep-alive
Cache-Control s-maxage=60, stale-while-revalidate
X-Cache CONFIG_NOCACHE
X-Powered-By Next.js
Strict-Transport-Security max-age=63072000; includeSubDomains; preload

About the tool

By using SecurityHeaders.info, you can quickly identify missing or misconfigured headers and take steps to secure your website, improving both security and user confidence.

This tool is widely used by developers, security professionals, and organizations to ensure their websites adhere to best practices in web security.

We also have another analytic tool that is used for identifying popularity metrics, general information about the business, finding similar products and competitors, and much more.

Watch it now at TrustRadar