HTTP Headers
Show the HTTP headers for a URL, with a full break-down of details. Will follow redirects.
Summary
- Response
- Total Requests
- 1
- Total Time
- 291 ms
https://vimeo.com/709363285- Status
- 200
- Message
- OK
- Time
- 291 ms
- IP
- 162.159.128.61
Timing
Wait
0 ms
DNS
3 ms
TCP
6 ms
Request
0 ms
First Byte
277 ms
Download
0 ms
Total
291 ms
HTTP Headers
- Date
Sat, 19 Sep 2026 08:47:27 GMT
The date and time that the message was sent.
- Content-Type
text/html; charset=utf-8
The MIME type of this content.
Problems were detected with this header
- Unknown MIME type.
- Connection
keep-alive
Control options for the current connection and list of hop-by-hop response fields.
keep-alive - The client would like to keep the connection open.
- Cf-Ray
a3d753602f500ce8-EWR
Encoded information about your request from Cloudflare.
- Cf-Cache-Status
BYPASS
Encoded information about your request from Cloudflare.
BYPASS - Cloudflare has been instructed to not cache this.
- Cache-Control
no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Inform all caching mechanisms from server to client whether they may cache this object.
no-store
May not be stored by any cache.
no-cache
May be stored by any cache but must be validated by the server.
must-revalidate
Stale caches must not be used.
post-check
0
Problems were found.
- Option is not one of known values.
pre-check
0
Problems were found.
- Option is not one of known values.
- Server
cloudflare
A name for the server.
cloudflare - Description of the server software.
- Strict-Transport-Security
max-age=31536000; includeSubDomains; preload
A HSTS Policy informing the HTTP client how long to cache the HTTPS only policy and whether this applies to subdomains.
Max-Age
31536000 (1 year)
The time a browser should remember a site can only be accessed with https (seconds).
includesubdomains
max-age applies to subdomains as well.
preload
Use Google's preloading strict transport security.
- Vary
Crossroads-Language, Accept-Encoding
Indicates that different content may be provided to different clients, depending on the vary header.
Headers
- Crossroads-Language
- Accept-Encoding
- Via
1.1 google
Added by proxies to track a request through proxies and to avoid loops.
Version
1.1
Protocol version.
Host
Host name.
- X-Backend
next
- X-Content-Type-Options
nosniff
Prevents Internet Explorer from MIME-sniffing a response away from the declared content-type.
nosniff - Block requests if type 'style' or 'script'.
- X-Edge-Version
8ededf1 2026-09-10T13:56:34.649Z
- X-Frame-Options
sameorigin
Clickjacking protection.
sameorigin - No rendering if origin mismatch.
- X-Link-Match
9
- X-Powered-By
Next.js
The software powering this site.
- X-Robots-Tag
noindex, nofollow
Specify how the resource is shown in search results.
noindex
Do not show this page in search results.
nofollow
Do not follow links on this page.
- X-Route
regex /^\/\d+(?:\/[0-9a-fA-F]+|\/report)?$/ HEAD
- X-Turnstile-Exception
3
- X-Vimeo-Edge
1
- X-Xss-Protection
1; mode=block
Cross-site scripting (XSS) filter.
1
Enable XSS filtering.
Mode
Filtering mode.
- block - Block page if XSS is detected.
- Set-Cookie
__cf_bm=c46nbstqLG8ym85nzESucP5t7F9RbG.h.M55.Rs8tRQ-1789807646.744754-1.0.1.1-SzINWtR9kWBHKUFhW.q6eOlieLjBbe9azazOZX5OA4fCJgqgO_L8VFdIh_ZxN13UOLRs49r7.PHnBDYKL2G0quMvwJYFETqyDuGglRlFBp4Ziy0QGYVV_ylpoOtGzVl.; HttpOnly; SameSite=None; Secure; Path=/; Domain=vimeo.com; Expires=Sat, 19 Sep 2026 09:17:27 GMT
A cookie sent from the server to be set on the client
__cf_bm
c46nbstqLG8ym85nzESucP5t7F9RbG.h.M55.Rs8tRQ-1789807646.744754-1.0.1.1-SzINWtR9kWBHKUFhW.q6eOlieLjBbe9azazOZX5OA4fCJgqgO_L8VFdIh_ZxN13UOLRs49r7.PHnBDYKL2G0quMvwJYFETqyDuGglRlFBp4Ziy0QGYVV_ylpoOtGzVl.
Cookie name and value.
HttpOnly
Prevents access to the cookie through JavaScript.
Samesite
None
Cookie sent with both cross-site and same-site requests..
Secure
The cookie is only sent when requesting from a https domain.
Path
/
The client will only send the cookie when requesting this path, or subdirectories, from the server.
Domain
vimeo.com
The client will only send the cookie when requesting from this domain.
Expires
Sat, 19 Sep 2026 09:17:27 GMT
When the cookie should expire.
- Alt-Svc
h3=":443"; ma=86400
Indicate a resource should be loaded from a different server while still appearing to be loaded from this server.
Service
- h3 - :443
Service
- ma - 86400 (1 day)
Max age for the alternative (seconds).
- ma - 86400 (1 day)