HTTP Headers
Show the HTTP headers for a URL, with a full break-down of details. Will follow redirects.
Summary
- Response
- Total Requests
- 1
- Total Time
- 1635 ms
https://manclub-m7.com/- Status
- 200
- Message
- OK
- Time
- 1635 ms
- IP
- 172.67.148.121
Timing
Wait
0 ms
DNS
11 ms
TCP
3 ms
Request
0 ms
First Byte
1606 ms
Download
1 ms
Total
1635 ms
HTTP Headers
- Date
Tue, 08 Sep 2026 19:54:46 GMT
The date and time that the message was sent.
- Content-Type
text/html; charset=UTF-8
The MIME type of this content.
Problems were detected with this header
- Unknown MIME type.
- Connection
keep-alive
Control options for the current connection and list of hop-by-hop response fields.
keep-alive - The client would like to keep the connection open.
- Server
cloudflare
A name for the server.
cloudflare - Description of the server software.
- Vary
Accept-Encoding
Indicates that different content may be provided to different clients, depending on the vary header.
Headers
- Accept-Encoding
- Link
<https://manclub-m7.com/wp-json/>; rel="https://api.w.org/"
Used to express a typed relationship with another resource.
Link
https://manclub-m7.com/wp-json/
- rel - https://api.w.org/
- Link
<https://manclub-m7.com/wp-json/wp/v2/pages/22>; rel="alternate"; title="JSON"; type="application/json"
Used to express a typed relationship with another resource.
Link
https://manclub-m7.com/wp-json/wp/v2/pages/22
- rel - alternate
- title - JSON
- type - application/json
- Link
<https://manclub-m7.com/>; rel=shortlink
Used to express a typed relationship with another resource.
Link
- rel - shortlink
- Strict-Transport-Security
max-age=63072000; includeSubdomains; preload
A HSTS Policy informing the HTTP client how long to cache the HTTPS only policy and whether this applies to subdomains.
Max-Age
63072000 (2 years)
The time a browser should remember a site can only be accessed with https (seconds).
includesubdomains
max-age applies to subdomains as well.
preload
Use Google's preloading strict transport security.
- X-Content-Type-Options
nosniff
Prevents Internet Explorer from MIME-sniffing a response away from the declared content-type.
nosniff - Block requests if type 'style' or 'script'.
- X-Frame-Options
SAMEORIGIN
Clickjacking protection.
SAMEORIGIN - No rendering if origin mismatch.
- Content-Security-Policy
default-src 'self' https: data: 'unsafe-inline' 'unsafe-eval'; worker-src 'self' blob:;
The content security policy allows the server to determine what resources the user is allowed to load.
Default-Src
Fallback for all fetches.
- 'self'
- https:
- data:
- 'unsafe-inline'
- 'unsafe-eval'
Worker-Src
Define sources for Worker, SharedWork, and ServiceWorker scripts.
- 'self'
- blob:
- Referrer-Policy
strict-origin-when-cross-origin
Controls what referrer information is sent with requests.
strict-origin-when-cross-origin - Send the full referrer for a same origin request. Send the origin only for cross-domain requests where the protocol level is the same. Otherwise do not send the referrer.
- Permissions-Policy
geolocation=(), microphone=(), camera=(), magnetometer=(), gyroscope=()
Enable and disable browser features.
geolocation
Control access to geo location API.
- () - Feature is disabled.
microphone
Control access to microphone device.
- () - Feature is disabled.
camera
Control access to camera.
- () - Feature is disabled.
magnetometer
Control access to magnetometer API.
- () - Feature is disabled.
gyroscope
Control access to gyroscope API.
- () - Feature is disabled.
- Cross-Origin-Opener-Policy
same-origin
Isolate the document from cross-origin windows.
same-origin - Isolated the browsing context to same-origin.
- Cross-Origin-Resource-Policy
same-origin
The cross-origin policy.
same-origin - Allow same origin requests only.
- Cross-Origin-Embedder-Policy
unsafe-none
- Cf-Cache-Status
DYNAMIC
Encoded information about your request from Cloudflare.
DYNAMIC - This is not cached by default.
- Server-Timing
cfCacheStatus;desc="DYNAMIC"
Server metrics for the request.
Cfcachestatus
DYNAMIC
- Server-Timing
cfEdge;dur=13,cfOrigin;dur=1589
Server metrics for the request.
Cfedge
- dur - 13
Cforigin
- dur - 1589
Problems were detected with this header
- Duplicate header. There is another header with this name and this may cause problems.
- Report-To
{"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=K5cEF92JEg%2F3FsE%2FFI80X8oy1xg1nQ3YMHZeKLYMfC%2FdrPL2j3FvvYUVlBTtFymAfZ95z3vl74zlTe%2BAxFzLoHRD%2BNmKItvEz5kleKn96obfBYG92injFGI9lpY37Exsrw%3D%3D"}]}
Report to.
Group
cf-nel
Max_age
604800
Endpoints
- {"url":"https://a.nel.cloudflare.com/report/v4?s=K5cEF92JEg%2F3FsE%2FFI80X8oy1xg1nQ3YMHZeKLYMfC%2FdrPL2j3FvvYUVlBTtFymAfZ95z3vl74zlTe%2BAxFzLoHRD%2BNmKItvEz5kleKn96obfBYG92injFGI9lpY37Exsrw%3D%3D"}
- Nel
{"report_to":"cf-nel","success_fraction":0.0,"max_age":604800}
Configure network request logging.
Report_to
cf-nel
Success_fraction
0Max_age
604800
- Cf-Ray
a38081bf0aa28ae3-EWR
Encoded information about your request from Cloudflare.
- Alt-Svc
h3=":443"; ma=86400
Indicate a resource should be loaded from a different server while still appearing to be loaded from this server.
Service
- h3 - :443
Service
- ma - 86400 (1 day)
Max age for the alternative (seconds).
- ma - 86400 (1 day)