HTTP Headers
Show the HTTP headers for a URL, with a full break-down of details. Will follow redirects.
Summary
- Response
- Total Requests
- 1
- Total Time
- 248 ms
https://sites.google.com/view/railroadcancersettlements- Status
- 200
- Message
- OK
- Time
- 248 ms
- IP
- 142.250.217.142
Timing
Wait
0 ms
DNS
9 ms
TCP
5 ms
Request
0 ms
First Byte
223 ms
Download
0 ms
Total
248 ms
HTTP Headers
- Content-Type
text/html; charset=utf-8
The MIME type of this content.
Type
text/html
Description
HTML file
Charset
utf-8
- X-Frame-Options
DENY
Clickjacking protection.
DENY - No rendering within frame.
- Vary
Sec-Fetch-Dest, Sec-Fetch-Mode, Sec-Fetch-Site
Indicates that different content may be provided to different clients, depending on the vary header.
Headers
- Sec-Fetch-Dest
- Sec-Fetch-Mode
- Sec-Fetch-Site
- Cache-Control
no-cache, no-store, max-age=0, must-revalidate
Inform all caching mechanisms from server to client whether they may cache this object.
no-cache
May be stored by any cache but must be validated by the server.
no-store
May not be stored by any cache.
Max-Age
0
The time a browser should remember a site can only be accessed with https (seconds).
must-revalidate
Stale caches must not be used.
- Pragma
no-cache
HTTP/1.0 backwards compatible cache handling.
no-cache - Force requests to the origin server before releasing a cache.
- Expires
Mon, 01 Jan 1990 00:00:00 GMT
The time at which the response is considered stale.
- Date
Tue, 10 Feb 2026 08:43:01 GMT
The date and time that the message was sent.
- Content-Length
0
The length of the response body in octets (8-bit bytes).
- P3p
CP="This is not a P3P policy! See g.co/p3phelp for more info."
P3P policy.
- Cross-Origin-Resource-Policy
same-site
The cross-origin policy.
same-site - Allow same site requests only.
- Content-Security-Policy
base-uri 'self';object-src 'none';report-uri /_/view/cspreport;script-src 'report-sample' 'nonce-6RPoYfc0q-nO8ljKOHXzQQ' 'unsafe-inline' 'unsafe-eval';worker-src 'self';frame-ancestors https://google-admin.corp.google.com/
The content security policy allows the server to determine what resources the user is allowed to load.
Base-URI
Define what can be used in the base element.
- 'self'
Object-Src
Define sources for object, embed, and applet elements.
- 'none'
Report-URI
/_/view/cspreport
URI for violation reports.
Script-Src
Define sources for JavaScript.
- 'report-sample'
- 'nonce-6RPoYfc0q-nO8ljKOHXzQQ'
- 'unsafe-inline'
- 'unsafe-eval'
Worker-Src
Define sources for Worker, SharedWork, and ServiceWorker scripts.
- 'self'
Frame-Ancestors
Define valid parents for frame, iframe, embed, object, and applet.
- https://google-admin.corp.google.com/
- Cross-Origin-Opener-Policy
unsafe-none
Isolate the document from cross-origin windows.
unsafe-none - Allow document to be added to its openered browsing context group.
- Origin-Trial
AsBCEoVg8pIwAkst2T88NNY429HzlH4fGwN+ALnF27Zl16u/ZR0Vylgws0om63IHSaH6pHPqY+k1GQ1sheqdhwgAAACGeyJvcmlnaW4iOiJodHRwczovL2dvb2dsZS5jb206NDQzIiwiZmVhdHVyZSI6IkRvY3VtZW50UG9saWN5SW5jbHVkZUpTQ2FsbFN0YWNrc0luQ3Jhc2hSZXBvcnRzIiwiZXhwaXJ5IjoxNzQ5NTEzNjAwLCJpc1N1YmRvbWFpbiI6dHJ1ZX0=
- Reporting-Endpoints
default="/web-reports?jobset=prod&wcrumsspbp=false&bl=editors.sites-viewer-frontend_20260128.02_p3&app=25&clss=1&context=eJwNyHtUVAUCx_HbnXt_uAhODCAjyetSNojaRGuSQMPsCMOqkWk2k3bURFRUEHmIj92Ek5p6ttZ2RdEeGOJGIvgsMK0MbMvX-sjWaFEoaYRhYB48ZsCS_f3xOed7vv416spRFqFutEWYE2IRXqag3RYhhh5WWIQx-y2CVGURQshw0iJY2izCCmp2WITvadE4q5BH_RFWQYq0CsWPW4VtlJVmFQqphN6i6fG3hYeESbeFSDL84hHNpC8dEBPJWTYgemnjaq9YRheTfeINOpfiEy_QYLZPfEgf7_KJx2jppSFxFeUJI-J68o0fEYWIEbF_w4j4Gz0zT6VKIkOZSmWmub-qVAtog3O6VEpiRbLkT2eOJktfU0ZiijSH3DON0hD9b_OfpHtUnm-SPqCs9SZpNYnHTZI_PfeZSTKSNz5NGqHEVWlSKj2xLk2aTFttadLfyDo1XVpCFz9Nl1pozztmqZpqqJHue82SkypWZ0gH6Z7mz1I3tfrNlDqoZF6lvIW6V1bKffRjQ6XcTjf6Dsot1K6pkjsp-sUqWUevtx6Sc-ivzkPyNjq7slpupiNrquWTdOletXyTtCcOy9F0NfNf8g8UuO1jOZTGRdXIMaR7tUbW01z7EXkBraON9ElmrXyCCrLq5U1kz62XPaQuscthdKDOLleR1eCQl9DCJoecRT9Ye-Q7pH6vRw4j1a8BGE3H1YFopAmNgZhCkV-NwQS6fWEM2uiFSjXmk-3wo-il2s4gnKKV9iDkk59eAzV9Xq9BEz2iBOMPdGpaMM5SamIwMijhTgim0-jMUATTPzaF4gDd3x4KJ22pGou36MnWsXiK_NeEQUPDeWHwXxuGndFavEsrpmrRla2Fm07XaXGOfBe1EC5p8ZePxmEr3aoah1Yq2RWOLTTsDIfoCscH3nAcpo7dj8FB5cbxOEALZ47HEmqrjcR3P0XiKumckdDTfHckFtC5hVE4szwKX5L9jSg4yX46Ch6a5ReNedSdE43exmgM0uZDMXiT6n-OwWc0wxmD2bTmKQVF9KxZQRKFFiuIoAfbFKi2Kzi7Q0EzrT6ooJC-uKqgiQL-oyCIvPQbpV9TMItqqI6CrisYS28_VFBOVU_H4gj9nhwLOSUWxw2xaCTXxlgM0IJbsVhKMy0TMJfuWSegm7yyDiN0FDqcJk-gDsOkDtIhhM7Ql6RM0mEifVulwzX6r02Hu9SojsN56giKg4NaguPwMz0IiYMqNA43hSRcrk3C97TsRBJySHUyCaPoMl2n2sxknKIRIQV-j6QgaXQKZlH-3hRsoH07n0cl-T9hgIamCakwUOukVHTQeVMqrlPshVTEU67JiGJqqTBi7yUjPqSu60a4qcxuxE56N92E_eReY8IQ-XWYEEDTHCYYyKmagREKnTMDERT4Gpvu9s6AjYKz0qGlFaXpWEux1emIp-e-S4eReorMGCDlqBkTyVNnxjCVtpuxg_45JQPvUXNbBi7T3V2_wEaalzoQTt_SNfIf6oCGCkpt2ETRTTbo6IrhPm6QNa8TSyi3uhPFpA_oQiL9vb0L-2jjYBfK6IbDjhZSNN2YSCc3dONz-qTBgRO0vsmBN2hvdg8-pFvv96CFepJ7MUCPN_QCO5xYl-KCssiFiVRb4MIpOvKmC9bdLuxrdcHR7oL-j26Ev-xGFNWWuzGmwo3Og25s_9SNvdQ224Mrqzw4v8eDbyi43gMtzQ_pg21xHzKX9uGr1H7kLu9HMb2yqR93NvfjpeZ-lFBadz8yKO7iACbTsdmDaKCh3EF0_TiIXvpokRfxK7z4d4APj0X4kKr44PfABzXZ9g9hkJ4_PgQDTf1pCNPpmDiMBpp28wHyW36HJmBUeVvtFTzaWLp1jypceiUnu0SZlL0sp2htQeGUwpyi7MLJ6_myCyYvL1ibV5Sdt2xxgj7hWf3TCYlT9AmL85_5P6US7lk&build-label=editors.sites-viewer-frontend_20260128.02_p3&imp-sid=CJbTn_LDzpIDFRzBzgAd_eI3IQ&is-cached-offline=false"
- Document-Policy
include-js-call-stacks-in-crash-reports
- Referrer-Policy
strict-origin-when-cross-origin
Controls what referrer information is sent with requests.
strict-origin-when-cross-origin - Send the full referrer for a same origin request. Send the origin only for cross-domain requests where the protocol level is the same. Otherwise do not send the referrer.
- Server
ESF
A name for the server.
ESF - Description of the server software.
- X-Xss-Protection
0
Cross-site scripting (XSS) filter.
0 - Disable XSS filtering.
- X-Content-Type-Options
nosniff
Prevents Internet Explorer from MIME-sniffing a response away from the declared content-type.
nosniff - Block requests if type 'style' or 'script'.
- Set-Cookie
NID=528=GXJoy_wJstUaNf8xmRzn0wQapQrrU7blYRPtp-KgzONbuQq2If94ApnD9uYGLJWHyd9dj-jwgWTpAu4VqYpJxvWEap9wlv1pPSZvWmyv10fXMyrGJwyj-qaZQU7fPTsp6CyQTLHLOpVsoBOLosXeg5MwKp1F40zxDnioiAKQCyzm78lyWYKXQkh1sDefpN4uQzlC3WL9Kv1NCZPjUfY; expires=Wed, 12-Aug-2026 08:43:01 GMT; path=/; domain=.google.com; Secure; HttpOnly; SameSite=none
A cookie sent from the server to be set on the client
NID
528
Cookie name and value.
Expires
Wed, 12-Aug-2026 08:43:01 GMT
When the cookie should expire.
Path
/
The client will only send the cookie when requesting this path, or subdirectories, from the server.
Domain
.google.com
The client will only send the cookie when requesting from this domain.
Secure
The cookie is only sent when requesting from a https domain.
HttpOnly
Prevents access to the cookie through JavaScript.
Samesite
none
Cookie sent with both cross-site and same-site requests..
- Alt-Svc
h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
Indicate a resource should be loaded from a different server while still appearing to be loaded from this server.
Service
- h3 - :443
Service
- ma - 2592000 (30 days)
Max age for the alternative (seconds).
- h3-29 - :443
HTTP/3 (draft 29)
- ma - 2592000 (30 days)
Service
- ma - 2592000 (30 days)
Max age for the alternative (seconds).
- ma - 2592000 (30 days)