HTTP Headers

Show the HTTP headers for a URL, with a full break-down of details. Will follow redirects.

Summary

Response
Total Requests
1
Total Time
144 ms
  • IP
    142.251.41.174
  • Timing

    Wait

    0 ms

    DNS

    8 ms

    TCP

    3 ms

    Request

    0 ms

    First Byte

    123 ms

    Download

    0 ms

    Total

    144 ms

  • HTTP Headers

    Content-Type

    text/html; charset=utf-8

    The MIME type of this content.

    Problems were detected with this header

    • Unknown MIME type.
    X-Frame-Options

    DENY

    Clickjacking protection.

    DENY - No rendering within frame.

    Vary

    Sec-Fetch-Dest, Sec-Fetch-Mode, Sec-Fetch-Site

    Indicates that different content may be provided to different clients, depending on the vary header.

    • Headers

      • Sec-Fetch-Dest
      • Sec-Fetch-Mode
      • Sec-Fetch-Site
    Cache-Control

    no-cache, no-store, max-age=0, must-revalidate

    Inform all caching mechanisms from server to client whether they may cache this object.

    • no-cache

      May be stored by any cache but must be validated by the server.

    • no-store

      May not be stored by any cache.

    • Max-Age

      0

      The time a browser should remember a site can only be accessed with https (seconds).

    • must-revalidate

      Stale caches must not be used.

    Pragma

    no-cache

    HTTP/1.0 backwards compatible cache handling.

    no-cache - Force requests to the origin server before releasing a cache.

    Expires

    Mon, 01 Jan 1990 00:00:00 GMT

    The time at which the response is considered stale.

    Date

    Fri, 28 Aug 2026 01:49:59 GMT

    The date and time that the message was sent.

    Content-Length

    0

    The length of the response body in octets (8-bit bytes).

    P3p

    CP="This is not a P3P policy! See g.co/p3phelp for more info."

    P3P policy.

    Content-Security-Policy

    base-uri 'self';object-src 'none';report-uri /_/view/cspreport;script-src 'report-sample' 'nonce-PtEenVlprgrOaeY4aB2xtg' 'unsafe-inline' 'unsafe-eval';worker-src 'self';frame-ancestors https://google-admin.corp.google.com/

    The content security policy allows the server to determine what resources the user is allowed to load.

    • Base-URI

      Define what can be used in the base element.

      • 'self'
    • Object-Src

      Define sources for object, embed, and applet elements.

      • 'none'
    • Report-URI

      /_/view/cspreport

      URI for violation reports.

    • Script-Src

      Define sources for JavaScript.

      • 'report-sample'
      • 'nonce-PtEenVlprgrOaeY4aB2xtg'
      • 'unsafe-inline'
      • 'unsafe-eval'
    • Worker-Src

      Define sources for Worker, SharedWork, and ServiceWorker scripts.

      • 'self'
    • Frame-Ancestors

      Define valid parents for frame, iframe, embed, object, and applet.

      • https://google-admin.corp.google.com/
    Cross-Origin-Resource-Policy

    same-site

    The cross-origin policy.

    same-site - Allow same site requests only.

    Cross-Origin-Opener-Policy

    unsafe-none

    Isolate the document from cross-origin windows.

    unsafe-none - Allow document to be added to its openered browsing context group.

    Reporting-Endpoints

    default="/web-reports?jobset=prod&wcrumsspbp=true&bl=editors.sites-viewer-frontend_20260824.02_p1&app=25&clss=1&context=eJwNz3dUlAcWBfBh-L73EIY-4wxtGL7BoSPYA9iCCisbYl0InmNBURFUpCiRNeoae6-w0SwuTlYUFBUU7GtZNRZQNGIUWyQWlF5kFJy9f_zOue_ev571OVW-VZzsiE2cbJwyTjYJHLfFybxAKIiTKSHLO162GsICamRfgAJrZFoY_kerPAqaVnbIP8L3KR_lK-HXiC75PehM6pJ_gYMbuuQlkHjTJJ8HLglf5F6wQGaWL4Yud7Nc5mGWt2eb5d0wfKWlZRRM-NPSMgGym8KEFSDPixCs4XRxhHAJoocMFcZBy9iRggme5HwtvILdaZHCzzBzcaSQAvJjkYI1fHUqUhgJQ-aNFkZAn0WjhSD48fVoYRPEDxwjTIddW6IEI7z5GCU0QV5KtLAfXjn9RXgPtTxWqIMlE_PF5fB-br7YBo_K88UXUB62X7wI99r2i7_DjNoDYjIsazogrobDqUbxBNx8ZRSr4U7sf8TfwMWzUPQC3-8KxRCQigvFCfWHxQTIgVVwKLZIPA7pM4-KS8F-Sb2ohvjhH8TpMOXyB3Em_BbfID4F-70Noho-H1SQZaGCjtnbUgUYKmwpGGqu2tFz-CbfniZD0VtHKoW59Y6UBmeOOtFlcC5zIjewkJypF5QOdqazMGKIM0VD6Qzc0O-pksJAFasiD9ixVEU_wfKC3rQWfGp7U19I1KppHlinqskJPi1AXqim9ToNbYeyIxo6Bw8KXKgWlmxwpeVQt82NPsCUse40HfyuulMoPC_S0o3HWroD72q11AiTW7SUAI_hOZyb4kkXZ3vSVaj_wZOaQC7oiCGGdTQRNk3T0S54n6yjxgoddULMbi-aCDkHvGgVHH3pRadgRKBE0ZDaV6JMGBQlUTh8Xi2R5RqJzq6T6Aqk7JcoA87fkegyKColcoSP0A1jqiSKgUI4Ao53JeoNm79ItBt6IvQkDtWTOVNPnKWn5u_11AHpS_W0BHJz9LQPVv5dT2sg4YGeEmFKl55mgtHbQMUwNs5AE0Db4UN6qBR86SEUky-VQautL30Ce0dfUsJpuADXC3ypCh6-9qVnUC0Lp1tF4XQfZh0Pp2SwPBFOVnAL7sKe0nAqio2gUkjbM5SyIXf9MMqHmF7DaSLor46gAHh3dyS1wMr6kbQeWlIjyQSzMiIpFQJXRdIA-J9qFN0B1bhR5AHPGkfRa5izYgwtBL1xDAVAQ2YUdYBUHEX-4Px7FLnBihdRtA52BkfTXrjyPJpugdu2P0gH7xpfUQs4ja8jV7gOVWBtqiMnaCh8TR0wr-g1pcPt4W_oHsz_9g1lwbE7b6gC5hvfUhZ8MNVTO0hO78kfDpV_oOOwJ6mB_gUNNQ3UAQ0RjdQBvuWN5LSuiXpKm0gsa6JFQ5tJmtpM_vDd7GaaAcWrmim3tpkaXjRTyIAWKtrdQnZ5LfTPky20K6KV9sGTv7bS7Xmt5Hy0lTQwWdlGF8e34Z82ej2tjWIT2yhuaTs9zWmnrOPttAwmXGmnbBj9vp2ioWp7B9VA5acOug_vHnVSI_x76kcKmPORrim6yM2ji0ZIXcSfu8geLggmuga1GhPVQdgoE30NN0tMNOyYiUaA4pGJlDDoMXZ4MuUzDa7-TMNPdFMUJL7spqczeuhPmL-vh9Jh7cEe2goJJ3soES6Ye-gabJB_oR1wRW2mW3BMaybX9WYyjJJxMLS0y9gEy00yXgu74iw4F1ynWvDmAgveDdevWbDuhgW_LJNzbKOcu5SWnKe25P2Q6mLJmVB60pJ1tgI3SALPmCVwMnTlCDztHwIPrhJ4FBRD_T2BrdxFThkkcm0rcR38km3Fh2DXD1YcvsaKB5ZZ8eLBvfjZp178ChZ8Zc2LYddba27pY8PfGGw4xc-Gz422YZ9JNryhzoarfBRcA-sGKHhOjIJdUxVsNio47RcFZ4H7eQVX3Ffwf-HlZVsur7blMzW2bPPMlm0hEFpc7LivwY4vwa9g9LPjYtAPteObb-y4Gkpn2nPWHns2qRy44lsHNsY78PksBw4sdOBg6FPiyEEwb7UTl1104uocZzZfd-a7i5Q8br-SK0qUrHis5K1_KvnAGyVrvVS8faCK3QepWAs6kMAbDOAL_hAIITAxSsWnclVs7NWbiy_1Zv9ANfeDtP5qzgZTvJq7JQ0Leg0bEzVcDKFnNbzmgoa3QMNzDb_q1PBbsDdpWA0zezR8WOfCm_q78Nz5Lrwl24X3wI4zLmzzyYV3R7jysHGuPBIiYeNBV17W48oFcMTfjUvgOJTCSSiHC4Fu3LnXjefedOM0OFfpxj-b3TigtweHFHjw-VNarjqt5Qdw6IyWEy5qORH8u7Vcae3JD8F9gCcHwtPBnpx61pMvPPHkazA3TMe3F-j4Acyv0nEuqO_qeOMLHe-Ea-zFleAW5cU6iF3hxduGSqz6UWIP0OyRuL-_njsz9PwFlq7W88HNei6BYXl6dvxJz9ONer7-Ts8ZTt5c5e7NDQ-82Rjbhy0u9uEzkoEvQ6a_gReD_UAD5wwysK7OwLnBPpwPnSk-bL7jw1zpw3X3ffgDdNb58v3-fmxzzo-d4UatH-9858d5sMjGn1fk-XOyIYA9kwN4_KoALjcG8LKxgfzicyDvUAex8UwQ33sWxKJDMF-J6csTC_vy0bBQXhsfyuthI2yCrbAdJs0J5eTuUHZSWF2vvvKAHF6U9GyzcBX-lpy0RApMmpWcuTA9IzgjOTMpI2gxuqT0oNnpCxdkJi2YNa1fSL9BIUP6DQgO6TctLfT_8bXSGw&build-label=editors.sites-viewer-frontend_20260824.02_p1&imp-sid=CIzrr9yawpYDFVBMqwIdtHAeYA&is-cached-offline=false"

    Document-Policy

    include-js-call-stacks-in-crash-reports

    Referrer-Policy

    strict-origin-when-cross-origin

    Controls what referrer information is sent with requests.

    strict-origin-when-cross-origin - Send the full referrer for a same origin request. Send the origin only for cross-domain requests where the protocol level is the same. Otherwise do not send the referrer.

    Server

    ESF

    A name for the server.

    ESF - Description of the server software.

    X-Xss-Protection

    0

    Cross-site scripting (XSS) filter.

    0 - Disable XSS filtering.

    X-Content-Type-Options

    nosniff

    Prevents Internet Explorer from MIME-sniffing a response away from the declared content-type.

    nosniff - Block requests if type 'style' or 'script'.

    Set-Cookie

    NID=534=NHGHdCfw3Qn0qeZYvzfAyMQ3mUzeUiTVOdcJTiNJd7YUtZysukyK_4Y6sdnpm0qRWFOnhaZdMtmjJtSa4H73abfwyhkT6SHyXHqrqEW-Kg5BHTO8rutGkFlxlLkrK4DZi8Gyn7JmOXHuJrSrjb4454DCpL1t-NfJzxge235JcubtO7kXt19QUd31W__2YQ4c0FmJKt6J; expires=Sat, 27-Feb-2027 01:49:59 GMT; path=/; domain=.google.com; Secure; HttpOnly; SameSite=none

    A cookie sent from the server to be set on the client

    • NID

      534

      Cookie name and value.

    • Expires

      Sat, 27-Feb-2027 01:49:59 GMT

      When the cookie should expire.

    • Path

      /

      The client will only send the cookie when requesting this path, or subdirectories, from the server.

    • Domain

      .google.com

      The client will only send the cookie when requesting from this domain.

    • Secure

      The cookie is only sent when requesting from a https domain.

    • HttpOnly

      Prevents access to the cookie through JavaScript.

    • Samesite

      none

      Cookie sent with both cross-site and same-site requests..

    Alt-Svc

    h3=":443"; ma=2592000,h3-29=":443"; ma=2592000

    Indicate a resource should be loaded from a different server while still appearing to be loaded from this server.

    • Service

      • h3 - :443
    • Service

      • ma - 2592000 (30 days)

        Max age for the alternative (seconds).

      • h3-29 - :443

        HTTP/3 (draft 29)

    • Service

      • ma - 2592000 (30 days)

        Max age for the alternative (seconds).