Content-Security-Policy
Defines the sources from which a document may load and execute different kinds of resources.
HTTP Scanner reference
Browse practical explanations of common HTTP response headers, including syntax, examples, implementation mistakes, and security considerations.
Check a website’s response headersDefines the sources from which a document may load and execute different kinds of resources.
Tells a browser to use HTTPS for future requests to the responding host over a stated period.
Controls whether a browser may infer a resource type other than the declared media type.
Specifies the conditions under which a response may be displayed within a frame or iframe.
Defines which portions of a referring URL a browser sends when it requests another resource.
Declares which browser features are available to the document and to embedded browsing contexts.
Sets the browsing-context group relationship between this document and cross-origin opened documents.
Specifies requirements for embedding cross-origin resources within a document.
Declares which origins may request a resource in certain cross-origin contexts.
Requests that a browser clear selected data types associated with the response origin.
Indicates whether the origin should use a dedicated browser agent cluster.
Describes a response policy for legacy cross-domain policy-file handling by compatible clients.
Controls whether compatible browsers may pre-resolve domain names referenced by a document.
Identifies software or services that handled the response on the server side.
Provides an optional label for the framework, runtime, or platform used to generate a response.
Reports the version of ASP.NET that generated the response when an application includes it.
Reports the server-side processing duration or runtime information for a response.
Provides an optional identifier for software that created the response content.
Lists intermediary protocols and hosts through which the message has been forwarded.
Defines directives that govern how browsers and intermediary caches store and reuse a response.
Indicates the estimated number of seconds a response has been stored in a cache.
Supplies a date and time after which a cached response is considered stale.
Provides an opaque identifier for a specific version of a resource representation.
Reports the date and time when the server considers the selected representation last changed.
Names request header fields that can cause caches to select a different stored response.
Declares the media type and optional character encoding of the response representation.
States the size in bytes of the response body when that size is known in advance.
Identifies the content codings applied to the representation before it is sent to the recipient.
Identifies the natural language or languages intended for the response representation.
Describes how a client should present a response, including an optional suggested file name.
Provides a URI that identifies a location associated with the selected representation.
Indicates whether the resource supports range requests and the unit used for those ranges.
Identifies the origin allowed to access the response from a cross-origin browser request.
Indicates whether a cross-origin browser request may include credentials in its response handling.
Lists the HTTP methods permitted for a cross-origin request in the relevant CORS context.
Lists request header fields permitted for a cross-origin request in the relevant CORS context.
Lists response header fields that browser scripts may access from a cross-origin response.
Specifies how long a browser may reuse the result of a CORS preflight request.
Instructs a client to store a cookie with attributes that define its scope and lifetime.
Describes one or more authentication challenges that a client may use for the requested resource.
Provides a URI used to identify a redirect target or the location of a newly created resource.
Indicates when a client may make another request after a response that asks it to wait.
Supplies typed relationships between the response and other resources identified by URIs.
Communicates named timing metrics collected while a server processed the request.
Identifies origins that may access detailed timing information for the response resource.