toblerone.com | Analytics by SecurityHeaders

HTTP Headers report for toblerone.com

Header Name Header Data
HTTP status code 200
Expires Sat, 01 Jan 2000 00:00:00 GMT
Cross-Origin-Embedder-Policy-Report-Only require-corp;report-to="coep_report"
Strict-Transport-Security max-age=31536000; preload; includeSubDomains
Content-Type text/html; charset="utf-8"
X-Fb-Debug 1yk+khdM52d+jqquqaHUxgpYxjb9URP5RB83pFc+bEPWfn8yVcXwvsxtddcr2Fnp+pO9Ylda21l8YOV8RyZx6w==
Cache-Control private, no-cache, no-store, must-revalidate
X-Frame-Options DENY
X-Content-Type-Options nosniff
Alt-Svc h3=":443"; ma=86400
Content-Length 0
Reporting-Endpoints coop_report="https://www.facebook.com/browser_reporting/coop/?minimize=0", coep_report="https://www.facebook.com/browser_reporting/coep/?minimize=0", default="https://www.instagram.com/error/ig_web_error_reports/?device_level=unknown&cpp=C3&cv=1021984354&st=1744924606067"
Report-To {"max_age":2592000,"endpoints":[{"url":"https:\/\/www.facebook.com\/browser_reporting\/coop\/?minimize=0"}],"group":"coop_report","include_subdomains":true}, {"max_age":86400,"endpoints":[{"url":"https:\/\/www.facebook.com\/browser_reporting\/coep\/?minimize=0"}],"group":"coep_report"}, {"max_age":259200,"endpoints":[{"url":"https:\/\/www.instagram.com\/error\/ig_web_error_reports\/?device_level=unknown&cpp=C3&cv=1021984354&st=1744924606067"}]}
Origin-Agent-Cluster ?1
X-Stack www
Date Thu, 17 Apr 2025 21:16:46 GMT
Proxy-Status http_request_error; e_fb_responsebytes="AcIxd2kk8_jKMHmtzj6lq-ryFdza3aglMfZfB8JlxAln3nVqcT8sUFnRpQ"; e_fb_requesttime="AcJcTiekYn5xnQmHU8eRgiAaSTgGk6UEwlWrIW-YbUrUMzuaMxKEGX4M1a2XYrW2hSl4Ki7xPQ"; e_proxy="AcKRSsEtJ6D1VHaHa_OcgAfQIZXH9ks3d__hrPo5JKeXT4P5y-g4lap3ITNdsPI2Vkd940qFl0WP17PDmZBq"; e_fb_twtaskhandle="AcIJJluZvbTP_spkNI52dRFIgH8Bv9dIaXpIObjPgChU7WVusHlIsxJsgJ2VVyXe7UFBJhSw7z9EI2OrHgzWoQLN1j1jaQb6OOVIUM2fQw"; e_fb_requestsequencenumber="AcJRofYgzf_HdtRkZYzEBebCbfPWPFiphIeeaxtfCkY7Zv3bzyQbzV97gcr2"; e_upip="AcK_qw6QAJ3GAdBws26tcrnKvv3erkMXn92G4ISUQO_lHvZdkQSEZA5hKUAjgV0ZUTIibnQgt0zvNJZQ2cpa0WgvEUqP6nskBUvJGHY"; e_fb_zone="AcL4WzBOJXXOr4rERB9titkH3OZpUee8VeyUjTNMlsfL0KSeYQ2gTteXo3mU4gdG"; e_fb_binaryversion="AcI_JiuIRnNPr68sROyMKNt5O0Ooxpci1aKXeZeOqkdRk5_YlYsHYM9GQjoFOgQW1GGl-r6x0C5X16rSf8BIJCHLE7uM4Q3kt0k"; e_fb_httpversion="AcKLDxifRpniEMYVXoejHLHltKLvza42lcnbC3K3VlGdsK8YRykBdlcIxupD"; e_fb_requesthandler="AcKAB9WTc8dq0zG7QfX6K-_IBCJaueE3K_QD8ngndDYA8B7kirnwq7rd2hr1rS8TUBqwhw_N9XxgnIU"; e_fb_configversion="AcJIK2hQca-NA3_vpVYalzW_QdmjOba7nXlVVYepaccHniNry9zixU-D32BpSw"; e_fb_vipaddr="AcIeZfpvgdwrq_c6Gu4iOWdHFz7nvmBqSGLs0kx7LaC1mkCNDSI6ukQOGFkN-DLuotmWE68pUO_1eSE2U1rjC5G1GJ4vojjvnrH-DALz"; e_fb_hostheader="AcLV_s2hAOL3v1BSx2bcZCilTKVuDhDn0LTHCXhWzbC57vhaoaxzdy69oS_ad5NeKr28m0trK5kpTWs"; e_fb_builduser="AcK72D57dz2zcmw24mCsrH7c8dCmHpuF5IaXfoNpsrZB_nFHqwlH0vIDIgleQ7OxF9c"; e_fb_vipport="AcL7w3Qx7DfBTs6RtrZvVKGeZqcj20ZmiKFzCiR9q4-ssjKlqqlTNBzo9-nW"; e_clientaddr="AcJ9tpFgYLx67FQpXdYCagygKtBn1B66pYei9RH_XKI4cW3v2z8mcY2SH2D9UvCuU9PIZ-cV4-zYDH8vHI3ybmMYfr03HCq3W_-jFk46hG-YaHiWJg", http_request_error; e_fb_responsebytes="AcKzpND4I_s3ZBNMemKiC1BcbIKCL29A9a5dk7NCWkPPTBjQF4DBqdYFfQ"; e_fb_requesttime="AcLrDV1Pi-UEC6z25s8NI06qkJfpWesLiktUNc84_og5JvewO0ZHEj4pxaFNlj-GfMj9mTU8_Q"; e_proxy="AcJfHzW6E70q5RGLQs4vOU50oka-SrTsQjQc5mValLp6UKc75VfYsN_aMIbJU18ZJRX8-tZ1XbMkL1X3"; e_fb_twtaskhandle="AcLyTIIZ1Y0xqXMg3guOKdGy4mJ_LzmP185ZVED2w-ryzLQW9X_GV6uFBlDyJI3eElt6u-LaYufFcv1pitUk9xAjF6mCaZrRk8Y"; e_fb_requestsequencenumber="AcL6XpduQLOGI5jeiXmyDWw7frx32__BMvPuYkFWg0H5EPKxdL8I76QNJg"; e_upip="AcIFJsBc-Rv8vrkcpgqWDB_WURp1NXFYo1hawiF2tp8Y4clKkxoGHCbDvjBfYObWWO9-SZPhAZOvtfleYVWDXfqY0YJ_vZAz6JSNJxpM"; e_fb_zone="AcJJFNK4QRJR1N6GOgrrF--8N30NrJ18I_3_hiK_6zsQIUOmwVzEhUV-SA7n-Q"; e_fb_binaryversion="AcKEIMz48rNH1e_BrJuCR0QhPn2IsBLgWsycqQgdScYQvXjOiCtaraRWtIQRpqdXmxlzx66nAmGURwH_93XZyOQ4cnNn3c2bqAE"; e_fb_httpversion="AcLB7fmwhHQ6Vapp8iSzkZ6Wy_eeGqxwKWbuxdQlrKxhSFGLMpCCyUmqTaJG"; e_fb_requesthandler="AcKpoTDIL3b4ULBb3uyGHWkT9_Sa3caeMiWHHxumQOXGt5L091fRPKU6tM9tlSjtCHGOPqYS300Jig"; e_fb_configversion="AcI-T7THmTENBUCd4x609rtARSKGiSTppIvS48dpetrP-7-Qz0oWv9bYp7KJDg"; e_fb_vipaddr="AcI0hxXrWLLwR06UGtRhjmOL78XriLetFxAx-h3ANUbLnWjuK7VXwHNPuspqZaORITPfe-GCh4L8"; e_fb_hostheader="AcLvdQhDG1A-gIzIFS2UI6DliFTZK0r0ORn21yz3tOzW50cdbii2CzeQUyN34qUZF0Rf2Pvw-CYmmEI"; e_fb_builduser="AcIB8Lyi-YGcn0j0l3i9xwjnexqgTMKBM8St7TbGDQmbcd1vlcfIETDgHPaZHxfxufI"; e_fb_vipport="AcJqqXiZ-Urssz4ckhUrV-MKit4i6XpEnnZMQBL-F3YDArGPK8fI0Ov7nWP2"; e_clientaddr="AcLT9yUJyQHsRcXnmtC8fSP1MALrTzyf3giEDo4Sxwnob4Ww5-Kh8loSpIlh_jk96LTAXy8UkF6DXd3GmQ"
Content-Security-Policy default-src *.facebook.com *.fbcdn.net *.instagram.com blob:;script-src *.instagram.com static.cdninstagram.com *.facebook.com *.fbcdn.net *.facebook.net 127.0.0.1:* 'nonce-dHcMZXHA' blob: data: 'self' 'unsafe-eval' https://*.google-analytics.com https://translate.google.com https://apis.google.com https://accounts.google.com;style-src *.instagram.com static.cdninstagram.com data: blob: 'unsafe-inline' *.fbcdn.net *.facebook.com;connect-src *.instagram.com wss://edge-chat.instagram.com connect.facebook.net *.facebook.com facebook.com *.fbcdn.net *.facebook.net wss://*.facebook.com:* ws://localhost:* blob: *.cdninstagram.com wss://*.instagram.com:* 'self';font-src *.instagram.com static.cdninstagram.com data: *.fbcdn.net *.intern.facebook.com *.facebook.com https://fonts.gstatic.com;img-src *.instagram.com *.facebook.com *.fbcdn.net data: *.cdninstagram.com *.whatsapp.net blob: *.fbsbx.com android-webview-video-poster: *.oculuscdn.com *.giphy.com www.googleadservices.com *.doubleclick.net *.google.com *.google.co.uk https://www.gstatic.com https://*.google-analytics.com;media-src *.facebook.com *.fbcdn.net *.instagram.com *.cdninstagram.com cdn.fbsbx.com data: blob: https://*.giphy.com;child-src *.facebook.com *.fbcdn.net *.instagram.com data: blob:;frame-src *.instagram.com *.facebook.com *.fbsbx.com fbsbx.com data: www.googleadservices.com *.doubleclick.net *.google.com *.google.co.uk;manifest-src *.facebook.com *.fbcdn.net *.instagram.com data: blob:;object-src *.facebook.com *.fbcdn.net *.instagram.com data: blob:;block-all-mixed-content;upgrade-insecure-requests;
X-Xss-Protection 0
Cross-Origin-Opener-Policy same-origin-allow-popups
Vary Sec-Fetch-Site, Sec-Fetch-Mode
X-Fb-Connection-Quality UNKNOWN; q=-1, rtt=-1, rtx=0, c=14, mss=1380, tbw=4106, tp=-1, tpl=-1, uplat=107, ullat=0
Connection keep-alive
Pragma no-cache

About the tool

By using SecurityHeaders.info, you can quickly identify missing or misconfigured headers and take steps to secure your website, improving both security and user confidence.

This tool is widely used by developers, security professionals, and organizations to ensure their websites adhere to best practices in web security.

We also have another analytic tool that is used for identifying popularity metrics, general information about the business, finding similar products and competitors, and much more.

Watch it now at TrustRadar