HTTP Headers for cnn.com

Score

J

Recommendations

Missing HeaderDescription
Strict-Transport-SecurityEnforces secure (HTTP over SSL/TLS) connections to the server.
X-Frame-OptionsIndicates whether a browser should be allowed to render a page in a <frame> or <iframe>.
Content-Security-PolicyHelps prevent Cross-Site Scripting (XSS) attacks.
X-Content-Type-OptionsPrevents browsers from MIME-sniffing a response away from the declared content-type.
Referrer-PolicyControls how much referrer information should be included with requests.
Permissions-PolicyManages which browser features and APIs a page can use.
X-XSS-ProtectionHelps protect against Cross-Site Scripting (XSS) attacks.
Expect-CTEnsures that browsers enforce Certificate Transparency.
Access-Control-Allow-OriginControls which origins are allowed to access resources on the server.

Raw Headers

Header NameValue
Connectionclose
Content-Length0
ServerVarnish
Retry-After0
Cache-Controlpublic, max-age=300
Locationhttp://www.cnn.com/
Accept-Rangesbytes
DateFri, 26 Jul 2024 00:55:26 GMT
Via1.1 varnish
set-cookieSecGpc=0; Domain=.cnn.com; Path=/; SameSite=Lax
Set-CookiegeoData=gunzenhausen|BY|91710|DE|EU|200|broadband|49.100|10.750|276005; Domain=.cnn.com; Path=/; SameSite=Lax
X-Served-Bycache-fra-etou8220066-FRA
X-CacheHIT
X-Cache-Hits0
alt-svch3=":443";ma=86400,h3-29=":443";ma=86400,h3-27=":443";ma=86400