HTTP Headers

Show the HTTP headers for a URL, with a full break-down of details. Will follow redirects.

Summary

Response
Total Requests
1
Total Time
130 ms
  • IP
    142.251.211.78
  • Timing

    Wait

    0 ms

    DNS

    3 ms

    TCP

    4 ms

    Request

    0 ms

    First Byte

    111 ms

    Download

    0 ms

    Total

    130 ms

  • HTTP Headers

    Content-Type

    text/html; charset=utf-8

    The MIME type of this content.

    Problems were detected with this header

    • Unknown MIME type.
    X-Frame-Options

    DENY

    Clickjacking protection.

    DENY - No rendering within frame.

    Vary

    Sec-Fetch-Dest, Sec-Fetch-Mode, Sec-Fetch-Site

    Indicates that different content may be provided to different clients, depending on the vary header.

    • Headers

      • Sec-Fetch-Dest
      • Sec-Fetch-Mode
      • Sec-Fetch-Site
    Cache-Control

    no-cache, no-store, max-age=0, must-revalidate

    Inform all caching mechanisms from server to client whether they may cache this object.

    • no-cache

      May be stored by any cache but must be validated by the server.

    • no-store

      May not be stored by any cache.

    • Max-Age

      0

      The time a browser should remember a site can only be accessed with https (seconds).

    • must-revalidate

      Stale caches must not be used.

    Pragma

    no-cache

    HTTP/1.0 backwards compatible cache handling.

    no-cache - Force requests to the origin server before releasing a cache.

    Expires

    Mon, 01 Jan 1990 00:00:00 GMT

    The time at which the response is considered stale.

    Date

    Sun, 02 Aug 2026 09:53:11 GMT

    The date and time that the message was sent.

    Content-Length

    0

    The length of the response body in octets (8-bit bytes).

    P3p

    CP="This is not a P3P policy! See g.co/p3phelp for more info."

    P3P policy.

    Content-Security-Policy

    base-uri 'self';object-src 'none';report-uri /_/view/cspreport;script-src 'report-sample' 'nonce-OoN4FPQxTJavZYRjwfgwRA' 'unsafe-inline' 'unsafe-eval';worker-src 'self';frame-ancestors https://google-admin.corp.google.com/

    The content security policy allows the server to determine what resources the user is allowed to load.

    • Base-URI

      Define what can be used in the base element.

      • 'self'
    • Object-Src

      Define sources for object, embed, and applet elements.

      • 'none'
    • Report-URI

      /_/view/cspreport

      URI for violation reports.

    • Script-Src

      Define sources for JavaScript.

      • 'report-sample'
      • 'nonce-OoN4FPQxTJavZYRjwfgwRA'
      • 'unsafe-inline'
      • 'unsafe-eval'
    • Worker-Src

      Define sources for Worker, SharedWork, and ServiceWorker scripts.

      • 'self'
    • Frame-Ancestors

      Define valid parents for frame, iframe, embed, object, and applet.

      • https://google-admin.corp.google.com/
    Cross-Origin-Resource-Policy

    same-site

    The cross-origin policy.

    same-site - Allow same site requests only.

    Cross-Origin-Opener-Policy

    unsafe-none

    Isolate the document from cross-origin windows.

    unsafe-none - Allow document to be added to its openered browsing context group.

    Reporting-Endpoints

    default="/web-reports?jobset=prod&wcrumsspbp=false&bl=editors.sites-viewer-frontend_20260727.02_p0&app=25&clss=1&context=eJwN0nlYzYkaB_DT6fd739RpP9Wp03L6nVSSNLbclimKutxpDOPWzfNYSmhBWoiukTHWB8OMyjPMRXKLsjSFjG0sl8FUsmUpWVKkfT9S3e8fnz--3-9f7_O8hpnKQwYRspNGEbJZygjZt2C-J0LmDEJuhEwJaS6Rss3gO7paNgTkWS1zhMA3nfJQaNvYI--DtQl98o1wx79fXgWXAvrlN6E3tl8-BPk7-uWnIfquTh4PtlFDcmdYIRuWr4Z--2G5zGFY3p0-LP8MgRv19UNh9jt9_ShIb_MVMkG-318whAtF_sI1CJscIMyCjhlTBB28yJgqvIWspGDhV4hZHSwkgPxMsGAIfzsXLEyByfHThCAYuWqaMAZ-aJgm7ITIidOFhbBvd6iQB419oUIb5CaECSfgrcXfhY9QwzOEelgz55C4AZ6ePyS-gqquw-IzWFRzVIyD9W1Hxc1wIjFP_A3uvs0TH0B5-H_Fx2DrVCA6g_u_CkRvkIoKxNlNJ8QoWAVr4Xh4oVgMyTGnxHVguqZJtIHIwGZxIcy73izGwOPIFrEWTA-0iDYwkK8g_QIFnTE1pjJwLTMmL6i-aUJ18NUhU5oLhe_NqQSWNZlTEvx-yoKug2WpBalBT7KkEVDiY0kXIWiyJYVBySJkGFerJF-wCrciB_hpnRX9AhtyrWkruNVY01gwTLQhC_i0woYMV9rQdo2K9kLpSRVdgke5tlQDa3bY0Qao36OmZpg3w54Wwqib9vQF1BU60p_PHakcPtQ4UivM7XCkKHgOdXBpnhNdXeJEN6HpOydqA7mgIYaZrKE5sHOBhvbBxzgNtZZpqBdmZjnTHMg46kyb4NRrZzoHQZ4ShUHiWIlSYVKoRH4wsFki_S0SXdwm0Q1IOCxRClwul-g6KCokMoc--AzTKyWaCQVwEszvS2QNu4YkyoJBfy2JAVoaTtUSp2mpfa2WeiB5nZbWQE6Glg7Cxn9raQtEPdJSNOS5uFIRzIhwpdng2ONGWqgQ3OkJFJE7lUKnsTt9AlNzd1LCBbgCkqc7ecDtXHeqhCcN7vQSHsj86F6hHz2ExcV-FAf6v_mRAdyD-5Bd4keF4f5UAknZAZQOOdu_pEMwc0QgzQHtzSAaDR_uT6EO2Ng0hbZDR2Iw6WBxSjAlguemYJoAXB9MCvifVQiVg9WsEHKAl60h1ABLM6fTStDmTafR0JIaSj0gFYWSB1g-CyU1ZL4KpW3ws1cYHYAbdWF0D9R73pAGPrS-pQ7YZl9Pu8Dim3qyg9tQCYY6dNBS0EA9EF_YQMnwV2AjVcHyrxspDc6UN1IZLM97T2kQ7_aBkmHi0ybyharmJnoGzbom6gbJ4iN5wPHzzVQM2bEt9B9oqW6hHmjxb6UecD_fShbb2miwpI3E0jZaFdBO0vx28oCYJe2UAEWb2imnpp2aX7WT94QOKszqIJP9HbTPv5MOwot_dNJf8Z1keaqTVDBX2UVXv-nCjV3UsKCLwqO7KGJdN9VmdFNacTethw0l3fQDzL7RTekw7WM3hUHl3h6qhopPPfQQPjztpVY45tBHJ-DI_D4avbSPbin6Se3QT0FSP_FAP5lCjUpH9eAboqOpcO-0jr48o6MgUDzVkRImPccOL-YNkM-DAYp-_ZlqFw3SO1h-cJCSYWv-IP0IUWcHKRquDA_SLdghH6Kf4IbNMN2DM47DZLd9mFxDZOwFG3Qy3gr7IvQ4B-zm6_GuXD3Ogtu39NjpTz1-XSrn8FY59yv1eb-NPh-GRFt9ToWSs_qsMRa4RRJ40WKB46AvQ-AF3wvsUylwCBRBU5XABvYiJ0wSuU5FXNOJd4b8KuZj6QZ8HPZ9Z8B-WwzYp9SAV_uM4JefRvBb-Pm9IXeMNOJwVyNOGGXEF6cZsdu3Rryj3ogr3RRcDdsnKHjpTAXbJSpYdkzB9pcVXPZQwX_A6-vGfP6BMf9ebcxGL43ZBDyhw9aEx7qa8DW4A3mjTLgItAEm_KjRhGugJMaU07JN-ZOVGZd9bcYnIs34cpoZexaYsRfUiebcCCNPm_MYiN9swaVXLfhuhiUP37bk-6uUPOuwkotPK7kMFM-V_OM7JR9tVLKjsxXvnWjF9pOs2BE0IIELuII7eIAneMOcUCs-l2PFeSOs-dpSay66Zs1J4204HXSRNvxZUrGgVfEXF1W85YqKd0NLnYpre1X8Bkx1KraBmEEVF2pseed4W1623JZ3p9tyNmT523HgLDsOgqmwM9-O1w_a8RE46aHm01AMJXAWzsMVTzX3HVBzzkk1H4Fld9WcBJcq1PzrsJpHWzuwd64D37ngyBUQddWRo8HjM7KhEz-BWh8nXuar4fI_NPwYlldqOAds7mv4FjtzBahDnVkDX2U689L3zrwnQGJVtsTjPbTcm6LlIVi3Wctf7tey-S9aXpin5RQLF660d-HmRy6cFz6SZVdHcqqHK68G04mu7Fzvyr0Jbtxb784Px4_iVUYenLnfgy2MDLbmX3pIZpkXBwzshH_Gxa6RPGMXx6WuTE7xSolLjU0ZsxpdbPKYJckrV6TGrli8YJz3uEnePuN8vLzHLUjy_j8X4JpX&build-label=editors.sites-viewer-frontend_20260727.02_p0&imp-sid=CKzz2p3WgZYDFQvJzgAd03UOBg&is-cached-offline=false"

    Document-Policy

    include-js-call-stacks-in-crash-reports

    Referrer-Policy

    strict-origin-when-cross-origin

    Controls what referrer information is sent with requests.

    strict-origin-when-cross-origin - Send the full referrer for a same origin request. Send the origin only for cross-domain requests where the protocol level is the same. Otherwise do not send the referrer.

    Server

    ESF

    A name for the server.

    ESF - Description of the server software.

    X-Xss-Protection

    0

    Cross-site scripting (XSS) filter.

    0 - Disable XSS filtering.

    X-Content-Type-Options

    nosniff

    Prevents Internet Explorer from MIME-sniffing a response away from the declared content-type.

    nosniff - Block requests if type 'style' or 'script'.

    Set-Cookie

    NID=533=fMPzsDjoGJT22wNE75nclH1lrYRp9MQO3Bi2R6m5C5bDZVXEOrlA1hyo3qn5Oe4pdudeJa31DfbBfj87wq_DQbSCyIG-dfniyiyHAW-kZiGovdyUWFFT2y8_gnZC-tal_42F1U4evJSKeRhlobvAdxmxfagjfNEyO6KtFTOG27wLwyEDMmo3eebWcMLkjj7nDUIzrTEP; expires=Mon, 01-Feb-2027 09:53:10 GMT; path=/; domain=.google.com; Secure; HttpOnly; SameSite=none

    A cookie sent from the server to be set on the client

    • NID

      533

      Cookie name and value.

    • Expires

      Mon, 01-Feb-2027 09:53:10 GMT

      When the cookie should expire.

    • Path

      /

      The client will only send the cookie when requesting this path, or subdirectories, from the server.

    • Domain

      .google.com

      The client will only send the cookie when requesting from this domain.

    • Secure

      The cookie is only sent when requesting from a https domain.

    • HttpOnly

      Prevents access to the cookie through JavaScript.

    • Samesite

      none

      Cookie sent with both cross-site and same-site requests..

    Alt-Svc

    h3=":443"; ma=2592000,h3-29=":443"; ma=2592000

    Indicate a resource should be loaded from a different server while still appearing to be loaded from this server.

    • Service

      • h3 - :443
    • Service

      • ma - 2592000 (30 days)

        Max age for the alternative (seconds).

      • h3-29 - :443

        HTTP/3 (draft 29)

    • Service

      • ma - 2592000 (30 days)

        Max age for the alternative (seconds).