theathletic.com | Analytics by SecurityHeaders

HTTP Headers report for theathletic.com

Header Name Header Data
HTTP status code 200
Age 0
Set-Cookie nyt-a=Auu3s2jm7Yzo46Ou0Fe3Rd; Expires=Tue, 07 Apr 2026 14:18:20 GMT; Path=/; Domain=.nytimes.com; SameSite=none; Secure
X-Nyt-Route ta-home-lohp
Content-Security-Policy upgrade-insecure-requests; default-src data: 'unsafe-inline' 'unsafe-eval' https:; script-src data: 'unsafe-inline' 'unsafe-eval' https: blob:; style-src data: 'unsafe-inline' https:; img-src data: https: blob: android-webview-video-poster:; font-src data: https:; connect-src data: https: wss: blob:; media-src data: https: blob:; object-src https:; child-src https: data: blob:; form-action https:; report-uri https://csp.nytimes.com/report;
Access-Control-Expose-Headers X-Nyt-Mktg-Group
X-Envoy-Upstream-Service-Time 583
X-Nyt-App-Webview 0
X-Cache-Hits 0
Content-Type text/html; charset=utf-8
X-Envoy-Decorator-Operation athletic.theathletic.nyti.nyt.net:443/*
X-Origin-Time 2025-04-07 14:18:20 UTC
X-Timer S1744035499.132547,VS0,VE1159
Access-Control-Allow-Origin *
X-Nyt-App-Map webview=false,preloaded=false
X-Ta-User-Logged-In false
X-Api-Version F-X
Strict-Transport-Security max-age=63072000; includeSubDomains; preload
Server envoy
Etag "85d71-PrPkVKavnsoGDdln5/r6KLAjtJo"
Accept-Ranges bytes
X-Cache MISS
X-Gdpr 1
Cache-Control public, max-age=1
Vary Accept-Encoding, Fastly-SSL
X-Nyt-Mktg-Group group4
X-Nyt-Edge-Cache MISS
Date Mon, 07 Apr 2025 14:18:20 GMT
Permissions-Policy browsing-topics=()
X-Served-By cache-ams2100103-AMS

About the tool

By using SecurityHeaders.info, you can quickly identify missing or misconfigured headers and take steps to secure your website, improving both security and user confidence.

This tool is widely used by developers, security professionals, and organizations to ensure their websites adhere to best practices in web security.

We also have another analytic tool that is used for identifying popularity metrics, general information about the business, finding similar products and competitors, and much more.

Watch it now at TrustRadar