HTTP Headers

Show the HTTP headers for a URL, with a full break-down of details. Will follow redirects.

Summary

Response
Total Requests
1
Total Time
137 ms
  • IP
    142.251.210.46
  • Timing

    Wait

    0 ms

    DNS

    3 ms

    TCP

    5 ms

    Request

    0 ms

    First Byte

    118 ms

    Download

    1 ms

    Total

    137 ms

  • HTTP Headers

    Content-Type

    text/html; charset=utf-8

    The MIME type of this content.

    • Type

      text/html

    • Description

      HTML file

    • Charset

      utf-8

    X-Frame-Options

    DENY

    Clickjacking protection.

    DENY - No rendering within frame.

    Vary

    Sec-Fetch-Dest, Sec-Fetch-Mode, Sec-Fetch-Site

    Indicates that different content may be provided to different clients, depending on the vary header.

    • Headers

      • Sec-Fetch-Dest
      • Sec-Fetch-Mode
      • Sec-Fetch-Site
    Cache-Control

    no-cache, no-store, max-age=0, must-revalidate

    Inform all caching mechanisms from server to client whether they may cache this object.

    • no-cache

      May be stored by any cache but must be validated by the server.

    • no-store

      May not be stored by any cache.

    • Max-Age

      0

      The time a browser should remember a site can only be accessed with https (seconds).

    • must-revalidate

      Stale caches must not be used.

    Pragma

    no-cache

    HTTP/1.0 backwards compatible cache handling.

    no-cache - Force requests to the origin server before releasing a cache.

    Expires

    Mon, 01 Jan 1990 00:00:00 GMT

    The time at which the response is considered stale.

    Date

    Sat, 02 May 2026 08:25:38 GMT

    The date and time that the message was sent.

    Content-Length

    0

    The length of the response body in octets (8-bit bytes).

    P3p

    CP="This is not a P3P policy! See g.co/p3phelp for more info."

    P3P policy.

    Cross-Origin-Resource-Policy

    same-site

    The cross-origin policy.

    same-site - Allow same site requests only.

    Content-Security-Policy

    base-uri 'self';object-src 'none';report-uri /_/view/cspreport;script-src 'report-sample' 'nonce-CFFRK0xQos8Pv5zJg6ZFFQ' 'unsafe-inline' 'unsafe-eval';worker-src 'self';frame-ancestors https://google-admin.corp.google.com/

    The content security policy allows the server to determine what resources the user is allowed to load.

    • Base-URI

      Define what can be used in the base element.

      • 'self'
    • Object-Src

      Define sources for object, embed, and applet elements.

      • 'none'
    • Report-URI

      /_/view/cspreport

      URI for violation reports.

    • Script-Src

      Define sources for JavaScript.

      • 'report-sample'
      • 'nonce-CFFRK0xQos8Pv5zJg6ZFFQ'
      • 'unsafe-inline'
      • 'unsafe-eval'
    • Worker-Src

      Define sources for Worker, SharedWork, and ServiceWorker scripts.

      • 'self'
    • Frame-Ancestors

      Define valid parents for frame, iframe, embed, object, and applet.

      • https://google-admin.corp.google.com/
    Cross-Origin-Opener-Policy

    unsafe-none

    Isolate the document from cross-origin windows.

    unsafe-none - Allow document to be added to its openered browsing context group.

    Reporting-Endpoints

    default="/web-reports?jobset=prod&wcrumsspbp=false&bl=editors.sites-viewer-frontend_20260427.03_p0&app=25&clss=1&context=eJwN0mdUlGcCxfFx5n3vgzC0gREkMMKMIliQNSoqIBIQiO5iW3cMnLUhGooNRVF2LTEY9Ww2DVE3RUVcEbAgqBjrir1hRwzNSFCQOggMILL3w-_L_9s951rmafZZGBVHrYyKGY5GxV_J_lujwoM-7DEqbPYaFVKmUeFIwSeNiuIGo-IxJQ-eq0ijicNLFR8II0oVOgr63aQMp-Yt7cpOWp_QqdxCtwLMyod0PtCsvEodsWblBzq806w8TotudynjaWDUB6UHLVf0KdeS2bVPqXDrU75L6VO-p5j9SlUCfTxbpfKnoC0qVTjN-kOliqKU5onSZlLuCZAs6WxegPQ_ihgfKM2g1qnBUhf9lvqJ9Ip2rQyRfqaYtSFSAilPhEiWNOF0iBRM4-OnSJNpyKop0kj6snaK9C-aOzZMWkC3ToVJZZT-73Api153hkvNlJkQIeXQK82n0lsqF1OlGlo3e5-8iZ6f2SdX08O2_XIZVWsy5TfkPj1T9qKF5QflOPpn80E5jc59niUXU05ilnySbr_Kkh-Rc_4h2Z3uRf5XfkrWaYdlLWmcs2UXGjgoW_Ygr8-yZV_S52XLs-pz5ChKpa10JDJXzqekmGPyBqpfdkw2ke26etmJ5gY1yAso-kqDHENP5zbKFWT7Y6PsRD2H1VBlq3HC1hpF5FlkDR9aVmeNZNJdsoEnlV61QRX9ZZ8t5lDuG3sU0Of19lhJwlcDW_r1mAZXqJ_eAf2pwM8B52jyeAdE0JGFDsin0RWOmEjaSC3c6PsNWvyHXm_Topk2ZQ7AVzS0fABGkWWiEzTUvdwJliucsMPdGd_R0rHOqIt1RisVHnXGeTLfcobitjP-cWAgvqQnmQNRTut2umAT_dzpgkNU8-1HaKDoqa5YQN5XXfEnqsrV4eYLHe5RXbkOTeTVrIMvzWnVIYpeUBWdjx6Es0sG4SLVbxyEZqovHAQTTRPumE1v49zRVOSODko96IGtdOylB05T4ig91tC4cD38SZushxv1pOmh2qbHue16FFPCfj1W04V7elwh9X097KmT3lNYiR7TKJuOkv0DPQbQ1x_02EW9AQbIgQacCDKgiFrWG9BOiRsMWEXfpRqQQVFPDFhEWYM9kUdTjZ6YRbr2oTDQfckLzygPXigkk7UXusnW3guOdJYukn6EF4bR3h-8cIBuZHqhhJ7VeqGSimy9cZlq7L3RQGUO3nhJPY7eUGm98Ujhjzu5_nhMi_P9EUeqk_6woDv0gDIK_JEbGYACWpkRiBTavWMS9pGfYjKCyHB1MobTspBgJFPZnmDsvx2MbKp7EIxW2lIfjB3UmhiCLhpyOgQjSdSEQE1-DSEIotSOEGyla9pQ3CPtjFC4UWVTKGpp6eYwrCBDVhiG04SbYQimxjXhaCd9XjiG0ebqcGynH3wi8CMVV0XgDlXu_B21VNX0Cq9JM7MGLnSDSsiyqwYaasyuRTvF59Yiie4GvcZDipn-Ggm0LOsNkil-aB2S6JvqOuymhw31KCO95i2G0ZEzDcinjNhG_EJPfmpEGTWWNqKdGgOa0E6eZ5qg2d6M3oJmyIXNWBXYAv28Fgyj3KQWFFDe1hbsLm9BQ3ULfMe0ImdXK2z2tCI9wISfqOLPJtyNN-FyugnXaP0uEzaSwzETnGmOYxsuzWzj1jbUzm9D5KI2GDe8Q0XqO8wsfocUmvL2HSLofnc7HpOd1IG65x1ookNuncihA_M6MXZpJ66rzfjIzYzJejNEjxm2NDG0C59Q7d4udNCd412YdKILQaR-3gVHGvuiCxNoWVQ3kqg0uhvl9Ft0D_we9eD-lfeopIqFvfiDok71YhFd7OvFdSp26sMdOqHrg8uOPlwo6cM18gxVCB9KN_YTu8llXj9x43o_4X6zn3hZqBSRTUphdlSJtZ-pxEYqOKUSOmtJpDlI4mtq1Eti3heS8CuRRCjlUf1DSVx6KgkLV1kkjJPFgQhZHCH3v8uiwhmi3R1C9oBY5Q-xnlyXQEyl0o0QVbS8FGItlZt4dVLECFGUIcRlOpRiIY5Q-kYL4b_NQowttBApfv1FZXd_8Yqir1mK9DeWonWIlYj0tBIJ3lbi3BQrsbPGSiydphYuiWqhOKQWrhfUouixWlymcb1qMYleXrEWv5ZaizFl1kJdaS2saQS1DrQRozxthCHQRuz9xkb8QskZtqJoup3ImWsnLiTbiRHZdsKH4tM0QlWuETKVrHIUM_Y7ivzjjqKIXMdphY70NJg8aXa4VmjUFl_UPyuBXfWDu41KF-lvcbHr9CNiF8etWZG02md13JrY1SPXssUmjVyStGL5mtjli-eP9h09znfMaD8f34_nr_T9P0kIbIc&build-label=editors.sites-viewer-frontend_20260427.03_p0&imp-sid=CMSPhIqXmpQDFRryzgAd1cM1Nw&is-cached-offline=false"

    Document-Policy

    include-js-call-stacks-in-crash-reports

    Referrer-Policy

    strict-origin-when-cross-origin

    Controls what referrer information is sent with requests.

    strict-origin-when-cross-origin - Send the full referrer for a same origin request. Send the origin only for cross-domain requests where the protocol level is the same. Otherwise do not send the referrer.

    Server

    ESF

    A name for the server.

    ESF - Description of the server software.

    X-Xss-Protection

    0

    Cross-site scripting (XSS) filter.

    0 - Disable XSS filtering.

    X-Content-Type-Options

    nosniff

    Prevents Internet Explorer from MIME-sniffing a response away from the declared content-type.

    nosniff - Block requests if type 'style' or 'script'.

    Set-Cookie

    NID=531=lkD0M1E9UthiUPB-cpOXJ3aYWdL2rC6Zz47studCH4l_jEstRS4whGQR78ld1Gd91pAwSUhb_j6pYfoaUHS-Tf0dNCgYvWROBK9mJOgla56zIy9FDLmg6WaaNC0m0chB_D0f0yhxrpEOSRkv9LuMcp9X4nlLImyl78v7PGxu_cXpR1g-M6CFljp986EjEr-mlLPI-TurBldjhy9QiHWD; expires=Sun, 01-Nov-2026 08:25:38 GMT; path=/; domain=.google.com; Secure; HttpOnly; SameSite=none

    A cookie sent from the server to be set on the client

    • NID

      531

      Cookie name and value.

    • Expires

      Sun, 01-Nov-2026 08:25:38 GMT

      When the cookie should expire.

    • Path

      /

      The client will only send the cookie when requesting this path, or subdirectories, from the server.

    • Domain

      .google.com

      The client will only send the cookie when requesting from this domain.

    • Secure

      The cookie is only sent when requesting from a https domain.

    • HttpOnly

      Prevents access to the cookie through JavaScript.

    • Samesite

      none

      Cookie sent with both cross-site and same-site requests..

    Alt-Svc

    h3=":443"; ma=2592000,h3-29=":443"; ma=2592000

    Indicate a resource should be loaded from a different server while still appearing to be loaded from this server.

    • Service

      • h3 - :443
    • Service

      • ma - 2592000 (30 days)

        Max age for the alternative (seconds).

      • h3-29 - :443

        HTTP/3 (draft 29)

    • Service

      • ma - 2592000 (30 days)

        Max age for the alternative (seconds).