Accent Color

HTTP Headers

Inspect HTTP request and response headers, including redirects.

28 /100
Security Score
F

Initial Request

t.co

Request Headers

GET / HTTP/2
Host:t.coCopied
user-agent:Mozilla/5.0 (Macintosh; Intel Mac OS X 10.14; rv:64.0) Gecko/20100101 Firefox/64.0Copied
accept:*/*Copied
accept-language:en-usCopied
connection:closeCopied

Response Headers

HTTP/2 404
date:Tue, 14 Jul 2026 19:34:45 GMTCopied
content-type:text/html;charset=utf-8Copied
server:cloudflare envoyCopied
cache-control:no-cache, no-store, max-age=0Copied
x-xss-protection:0Copied
content-security-policy:default-src 'none'; img-src https://abs.twimg.com; script-src https://abs.twimg.com about:; style-src https://abs.twimg.com 'unsafe-inline'; font-src https://abs.twimg.com https://twitter.com; connect-src 'none'; object-src 'none'; media-src 'none'; frame-src 'none'; report-uri https://twitter.com/i/csp_report?a=ORTGK%3D%3D%3D&ro=falseCopied
set-cookie:__cf_bm=4_DuNKib948dtSjBVMBEYQgP8CwAiQdAHF9VRaRiQK0-1784057685.0143237-1.0.1.1-UGqHxu9iKcaYqLl0P4ONQbqc0tXlcVkvCqpjpRdEakrvVu__7O7jYUvvo7c1UVpD61mqDEWKRGmj10Ue8ZvVgW0TERVxvDzLY1.0s8CtzKt_pOeEdbIrdeIp0KVLuNvd; HttpOnly; SameSite=None; Secure; Path=/; Domain=t.co; Expires=Tue, 14 Jul 2026 20:04:45 GMTCopied
x-response-time:11Copied
origin-cf-ray:a1b2f77358fa9c18-IADCopied
strict-transport-security:max-age=631138519; includeSubdomainsCopied
x-served-by:t4_aCopied
cf-cache-status:DYNAMICCopied
vary:accept-encodingCopied
cf-ray:a1b2f77358fa9c18-IADCopied

Core Security Headers

Strict-Transport-Security (HSTS)
Forces browsers to use HTTPS for all future requests to this domain.
Content-Security-Policy (CSP)
Controls which resources the browser is allowed to load, mitigating XSS attacks.
X-Frame-Options
Prevents the page from being embedded in iframes, blocking clickjacking attacks.
X-Frame-Options: DENY
X-Content-Type-Options
Prevents browsers from MIME-sniffing responses, reducing drive-by download attacks.
X-Content-Type-Options: nosniff
Referrer-Policy
Controls how much referrer information is sent with requests.
Referrer-Policy: strict-origin-when-cross-origin
Permissions-Policy
Controls which browser features and APIs the site can use (camera, mic, geolocation, etc).
Permissions-Policy: camera=(), microphone=(), geolocation=()

Bonus Headers

Cross-Origin-Embedder-Policy (COEP)
Requires resources to explicitly grant permission to be loaded cross-origin.
Cross-Origin-Embedder-Policy: require-corp
Cross-Origin-Opener-Policy (COOP)
Isolates the browsing context to prevent cross-origin attacks.
Cross-Origin-Opener-Policy: same-origin
Cross-Origin-Resource-Policy (CORP)
Controls which origins can read a resource, preventing speculative side-channel attacks.
Cross-Origin-Resource-Policy: same-origin

⚠️ Warnings

⚠️
X-XSS-Protection is deprecated
The X-XSS-Protection header is deprecated and can introduce vulnerabilities in older browsers. Use Content-Security-Policy instead.
--- REQUEST ---
GET / HTTP/2
Host: t.co
user-agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.14; rv:64.0) Gecko/20100101 
Firefox/64.0
accept: */*
accept-language: en-us
connection: close

--- RESPONSE ---
HTTP/2 404 
date: Tue, 14 Jul 2026 19:34:45 GMT
content-type: text/html;charset=utf-8
server: cloudflare envoy
cache-control: no-cache, no-store, max-age=0
x-xss-protection: 0
content-security-policy: default-src 'none'; img-src https://abs.twimg.com; script
-src https://abs.twimg.com about:; style-src https://abs.twimg.com 'unsafe-inline'
; font-src https://abs.twimg.com https://twitter.com; connect-src 'none'; object-s
rc 'none'; media-src 'none'; frame-src 'none'; report-uri https://twitter.com/i/cs
p_report?a=ORTGK%3D%3D%3D&ro=false
set-cookie: __cf_bm=4_DuNKib948dtSjBVMBEYQgP8CwAiQdAHF9VRaRiQK0-1784057685.0143237
-1.0.1.1-UGqHxu9iKcaYqLl0P4ONQbqc0tXlcVkvCqpjpRdEakrvVu__7O7jYUvvo7c1UVpD61mqDEWKR
Gmj10Ue8ZvVgW0TERVxvDzLY1.0s8CtzKt_pOeEdbIrdeIp0KVLuNvd; HttpOnly; SameSite=None; 
Secure; Path=/; Domain=t.co; Expires=Tue, 14 Jul 2026 20:04:45 GMT
x-response-time: 11
origin-cf-ray: a1b2f77358fa9c18-IAD
strict-transport-security: max-age=631138519; includeSubdomains
x-served-by: t4_a
cf-cache-status: DYNAMIC
vary: accept-encoding
cf-ray: a1b2f77358fa9c18-IAD