HTTP Headers for nbc.com

Score

I

Recommendations

Missing HeaderDescription
Strict-Transport-SecurityEnforces secure (HTTP over SSL/TLS) connections to the server.
Content-Security-PolicyHelps prevent Cross-Site Scripting (XSS) attacks.
X-Content-Type-OptionsPrevents browsers from MIME-sniffing a response away from the declared content-type.
Referrer-PolicyControls how much referrer information should be included with requests.
Permissions-PolicyManages which browser features and APIs a page can use.
X-XSS-ProtectionHelps protect against Cross-Site Scripting (XSS) attacks.
Expect-CTEnsures that browsers enforce Certificate Transparency.
Cache-ControlDirects caching mechanisms on how to handle the response.

Raw Headers

Header NameValue
ServerAkamaiGHost
Content-Length0
Locationhttps://www.nbc.com/
DateFri, 26 Jul 2024 00:55:44 GMT
Connectionkeep-alive
Akamai-Request-BC[a=104.114.76.174,b=812015177,c=g,n=US_CA_SANJOSE,o=20940]
X-Frame-OptionsSAMEORIGIN
Akamai-Cache-StatusRedirect from child
Akamai-GRN0.ae4c7268.1721955344.30665e49
Access-Control-Allow-Origin*
Server-Timingak_p; desc="1721955344423_1752321198_812015177_12_7534_153_0_-";dur=1
content-typetext/html
x-powered-bygeneretic-1.232.10
last-modifiedFri, 26 Jul 2024 00:54:18 GMT
etagW/"fc4ed-dNfJtD01iN9TdfDGEuAunePCAE4"
mpulse_cdn_cacheMISS
mpulse_origin_time611
cache-controlpublic, max-age=208
dateFri, 26 Jul 2024 01:31:44 GMT
alt-svch3=":443"; ma=93600
akamai-request-bc[a=23.53.42.15,b=153217886,c=g,n=DE_HE_FRANKFURT,o=20940]
x-frame-optionsSAMEORIGIN
varyUser-Agent
strict-transport-securitymax-age=86400
akamai-cache-statusError from child
akamai-grn0.0f2a3517.1721957504.921eb5e
access-control-allow-origin*
server-timingak_p; desc="1721957504511_389360143_153217886_22_4419_7_12_15";dur=1
serverAkamaiGHost
mime-version1.0
content-length361
expiresFri, 26 Jul 2024 01:31:44 GMT