HTTP Headers for arstechnica.com

Responds with HTTP 200 — 4 of 6 security headers present.

Domain to Check
200 https://arstechnica.com/
Security Headers4/6
HSTS
CSP
X-Frame-Options
X-Content-Type-Options
Referrer-Policy
Permissions-Policy
All Response Headers (11)
connectionclose
content-encodingbr
content-security-policydefault-src https: data: 'unsafe-inline' 'unsafe-eval'; child-src https: data: blob:; connect-src https: data: blob:; font-src https: data:; img-src https: data: blob:; media-src blob: data: https:; object-src https:; script-src https: data: blob: 'unsafe-inline' 'unsafe-eval'; style-src https: 'unsafe-inline'; block-all-mixed-content; upgrade-insecure-requests
content-typetext/html; charset=UTF-8
dateFri, 24 Apr 2026 13:00:41 GMT
permissions-policylocal-network-access=()
set-cookiears_session=a5cee76dffc84bd33345554b2f2eaa4d; Max-Age=1800; Path=/; HttpOnly; Secure
varyAccept-Encoding
x-content-type-optionsnosniff
x-frame-optionsSAMEORIGIN
x-xss-protection1; mode=block
Related