HTTP Headers
Show the HTTP headers for a URL, with a full break-down of details. Will follow redirects.
Summary
- Response
- Total Requests
- 1
- Total Time
- 156 ms
https://sites.google.com/view/railroadcancersettlements- Status
- 200
- Message
- OK
- Time
- 156 ms
- IP
- 142.250.191.14
Timing
Wait
0 ms
DNS
10 ms
TCP
4 ms
Request
1 ms
First Byte
129 ms
Download
1 ms
Total
156 ms
HTTP Headers
- Content-Type
text/html; charset=utf-8
The MIME type of this content.
Type
text/html
Description
HTML file
Charset
utf-8
- X-Frame-Options
DENY
Clickjacking protection.
DENY - No rendering within frame.
- Vary
Sec-Fetch-Dest, Sec-Fetch-Mode, Sec-Fetch-Site
Indicates that different content may be provided to different clients, depending on the vary header.
Headers
- Sec-Fetch-Dest
- Sec-Fetch-Mode
- Sec-Fetch-Site
- Cache-Control
no-cache, no-store, max-age=0, must-revalidate
Inform all caching mechanisms from server to client whether they may cache this object.
no-cache
May be stored by any cache but must be validated by the server.
no-store
May not be stored by any cache.
Max-Age
0
The time a browser should remember a site can only be accessed with https (seconds).
must-revalidate
Stale caches must not be used.
- Pragma
no-cache
HTTP/1.0 backwards compatible cache handling.
no-cache - Force requests to the origin server before releasing a cache.
- Expires
Mon, 01 Jan 1990 00:00:00 GMT
The time at which the response is considered stale.
- Date
Thu, 25 Dec 2025 20:17:30 GMT
The date and time that the message was sent.
- Content-Length
0
The length of the response body in octets (8-bit bytes).
- P3p
CP="This is not a P3P policy! See g.co/p3phelp for more info."
P3P policy.
- Cross-Origin-Resource-Policy
same-site
The cross-origin policy.
same-site - Allow same site requests only.
- Cross-Origin-Opener-Policy
unsafe-none
Isolate the document from cross-origin windows.
unsafe-none - Allow document to be added to its openered browsing context group.
- Content-Security-Policy
base-uri 'self';object-src 'none';report-uri /_/view/cspreport;script-src 'report-sample' 'nonce-OUcxGZd4_Ou4vsH3TcQIdA' 'unsafe-inline' 'unsafe-eval';worker-src 'self';frame-ancestors https://google-admin.corp.google.com/
The content security policy allows the server to determine what resources the user is allowed to load.
Base-URI
Define what can be used in the base element.
- 'self'
Object-Src
Define sources for object, embed, and applet elements.
- 'none'
Report-URI
/_/view/cspreport
URI for violation reports.
Script-Src
Define sources for JavaScript.
- 'report-sample'
- 'nonce-OUcxGZd4_Ou4vsH3TcQIdA'
- 'unsafe-inline'
- 'unsafe-eval'
Worker-Src
Define sources for Worker, SharedWork, and ServiceWorker scripts.
- 'self'
Frame-Ancestors
Define valid parents for frame, iframe, embed, object, and applet.
- https://google-admin.corp.google.com/
- Origin-Trial
AsBCEoVg8pIwAkst2T88NNY429HzlH4fGwN+ALnF27Zl16u/ZR0Vylgws0om63IHSaH6pHPqY+k1GQ1sheqdhwgAAACGeyJvcmlnaW4iOiJodHRwczovL2dvb2dsZS5jb206NDQzIiwiZmVhdHVyZSI6IkRvY3VtZW50UG9saWN5SW5jbHVkZUpTQ2FsbFN0YWNrc0luQ3Jhc2hSZXBvcnRzIiwiZXhwaXJ5IjoxNzQ5NTEzNjAwLCJpc1N1YmRvbWFpbiI6dHJ1ZX0=
- Reporting-Endpoints
default="/web-reports?jobset=prod&wcrumsspbp=false&bl=editors.sites-viewer-frontend_20251210.02_p1&app=25&clss=1&context=eJwNz31czAcAx_Gfu9_vi0i6iqtR53fYJQ-nzUS1aqe7hpmHcTf2UuQkD0WlPGzUizyNvbB5HtkJKXl-yLCZbPMwo2GW5Tmn57vrQXmY9v3j_Xp9Xt__vm4HO-W0MwuFHczCaG-z8Bl5rjcLPejtVrPQaZtZEG1mwZsijpkF80OzkEDFNWbhFk32tQhJ1NjdIoj-FmF-T4uQTfHRFiGVMmglDQ26K7wl9L0r-FPEk3qFifSZTYoQcmQ1KZpp4axmRRZdCWtRlNC58BbFJXphbVG8pf1rWhSHaerVl4qZlCS0KtKppVurQujeqmhc0Kp4Q--NUypDKSJLqTTR2GdK5URa4BgqZpJia5joRmcOhom_UExIuDiaXMOjxJf07-KPxKeUDIOYQZvmGsSdFJ9uEGeR4ohBdKMhpwxiFDUHRYutFDIzWoykXvOixX603B4triXLIKMYR1dOGsVS-u4bk5hLeVREz5tNooNss2LEfHqq-lisprK2w8VyyhiXIy2lf07nSI-opGG3VEqPVDapgjSf2iQdTSnbIyXSV449UjadnZErFVP-7FzpGF19miv9ReqjeyUNXR-1T7pD7tn7JR_yDciTepDu8zxJT2Or8qWJdGBUgXSUHk8rkCrpfF6B9CuVXCiUSikl_pC0iKrmHJLqaXthlWSjy5erpZtkiaiR4mjSxRopnu5YaqX75LGjVupKymcd0YGOeLijiHoXuaM_3b3UCQ8pPdgDS-iTHA-MJ_vezqijggpPHKcZVZ6YS231KnhQG9kL7en4YC-cpcgQL8TQgSleOErB970xlNJVPlhCGxf5YDs9X-EDBy21dcFKeresCwaQ2-yuUNGrpK5wS-6K1Ro1NlDCIDUqrWq46EShGueo5YoawlU1vvzBF8vpts0XZZSxxg9L6ZXDDwqnH3Y2-2Evla9_BzW0KaobttOk4d0QR3cK_HH5nj-uk87hDz2Nd_ljIp2aFIAz0wPwE1WdCEA9jWirwTg6PljDzxo8TtSgrkiDF7R4Tw8so2GOHhhJswfISKMPTDJCyWe-jO70OluGcoWMs6tkFNOs3TJS6fx1GRep458yPKmZ3pDxhowRlEeF5HlTRhda91bGJrIN1CKf_gvTQgrX4kiEFkVUk6hFIzkXatFEE29rMZViD_dEAjWe6Ik3NNzcG2PpqaU3qqneXYdX1N5Th04k99WhD_1u0-EG_W3X4QEVeQTiApV7BqKGSr0C8ZheewdC6ROIEiEU1wpCcYsKRoXhOLUK4WjbJhyhHcIxguZuDscCmqT-EPFUtvFDlJNVGYGZ5NYrAioq6xuJcrpgiMRN0l6KRBDNMURhPpVujULlzSi4KKsqCqtpma8BX9MGowHbqIvVADW5ZhvwkhzKYWgln9HD0J3cv2DTg7phsJNXvBFqSsg0Ipm0uUYE0a79RuyjIZeNiKLaNBOaSD5oQh-qLzThFWU-MmEVfds_Bjuo-GEMrtGDNU9gp9iKJ5hGqjHl8CO3l-VQ0ZZ-dnxPKZl2LCLNRTt0ZEmqQBzNya3AfNJ3rEQILXxRiSzaeb8Ke6mkpgqlZJ1QjWMLqvEjPV9XjfiAWsygzdZa7KLasDo0Ue_TdVCtcuDgEQdO0LxwJ-TJTvShtGQn8pc58WytE5b1Tmwpc6LmkRP6912Im-7CDGrY5MJryj7pwja6P7Ief8ysh9eheqhpvHcD7LENGDW1AT9HNmLCokaULW7EmOJGZNDuyc0ISmjGbx1bECm3QNWh3b3Tp66i89bcnLF-4oREa4bc1zotMS05JbV_amKaNbVfOjdrSr_pKclJadakabHB-uBBA4MH6vvrg2PnDvwfYMuxGg&build-label=editors.sites-viewer-frontend_20251210.02_p1&imp-sid=CN_q9brH2ZEDFeZJqwId74QBIQ&is-cached-offline=false"
- Document-Policy
include-js-call-stacks-in-crash-reports
- Referrer-Policy
strict-origin-when-cross-origin
Controls what referrer information is sent with requests.
strict-origin-when-cross-origin - Send the full referrer for a same origin request. Send the origin only for cross-domain requests where the protocol level is the same. Otherwise do not send the referrer.
- Server
ESF
A name for the server.
ESF - Description of the server software.
- X-Xss-Protection
0
Cross-site scripting (XSS) filter.
0 - Disable XSS filtering.
- X-Content-Type-Options
nosniff
Prevents Internet Explorer from MIME-sniffing a response away from the declared content-type.
nosniff - Block requests if type 'style' or 'script'.
- Set-Cookie
NID=527=qS1_czL1d1kPbxda6E64xnjTZzntv0_6Ts_yL0ACBfpYYDpRpvMePy1vy9iiGyX_PcHZMkANsxUMqzxhPCoBAU2SBPnthln5DY4N00ZcB27Z-y3PyXswn5g1CPwDSf0SnL0K7MlQwJlrKw11H0mjjT5L122BuxoeUSixp6LbJ_O4gzTO_-hGEBt7MS6gR11zv_8S_GhPfvMnY3DjX_A; expires=Fri, 26-Jun-2026 20:17:30 GMT; path=/; domain=.google.com; Secure; HttpOnly; SameSite=none
A cookie sent from the server to be set on the client
NID
527
Cookie name and value.
Expires
Fri, 26-Jun-2026 20:17:30 GMT
When the cookie should expire.
Path
/
The client will only send the cookie when requesting this path, or subdirectories, from the server.
Domain
.google.com
The client will only send the cookie when requesting from this domain.
Secure
The cookie is only sent when requesting from a https domain.
HttpOnly
Prevents access to the cookie through JavaScript.
Samesite
none
Cookie sent with both cross-site and same-site requests..
- Alt-Svc
h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
Indicate a resource should be loaded from a different server while still appearing to be loaded from this server.
Service
- h3 - :443
Service
- ma - 2592000 (30 days)
Max age for the alternative (seconds).
- h3-29 - :443
HTTP/3 (draft 29)
- ma - 2592000 (30 days)
Service
- ma - 2592000 (30 days)
Max age for the alternative (seconds).
- ma - 2592000 (30 days)