HTTP Headers for atlassian.com

Responds with HTTP 200 OK from AtlassianEdge — 4 of 6 security headers present.

Domain to Check
200 OKhttps://www.atlassian.com/
Security Headers4/6
HSTS
CSP
X-Frame-Options
X-Content-Type-Options
Referrer-Policy
Permissions-Policy
All Response Headers (28)
age455
alt-svch3=":443"; ma=86400
atl-request-ide65b92e4-2a1a-4a08-8916-eaee5ab64415
atl-traceide65b92e42a1a4a088916eaee5ab64415
cache-controlmax-age=0, s-maxage=1200, stale-while-revalidate=1200, stale-if-error=1200, no-cache="Set-Cookie"
connectionclose
content-encodingbr
content-security-policybase-uri 'self'; default-src 'self' *.atlassian.com *.intercomcdn.com *.orangelogic.com *.6sc.co *.6sense.com sourcetreeapp.com *.sourcetreeapp.com; script-src 'self' *.gstatic.com *.cookielaw.org *.public.atl-paas.net *.prod.atl-paas.net *.googletagmanager.com *.marketo.net *.atlassian.com utt.impactcdn.com *.google.com *.doubleclick.com *.googleadservices.com *.livechatinc.com *.bing.com *.quora.com *.yimg.jp *.clicktale.net *.linkedin.com *.twitter.com *.licdn.com *.demandbase.com *.doubleclick.net *.facebook.net *.redditstatic.com *.clearbitscripts.com *.clarity.ms *.vimeo.com *.google-analytics.com facebook.com *.facebook.com impactcdn.com *.impactcdn.com clearbitjs.com *.clearbitjs.com yahoo.co.jp *.yahoo.co.jp *.recaptcha.net *.ads-twitter.com *.intercom.io *.intercomcdn.com *.jsdelivr.net *.6sc.co *.6sense.com *.techtarget.com *.capterra.com sourcetreeapp.com *.sourcetreeapp.com 'unsafe-eval' 'unsafe-inline'; style-src 'self' *.public.atl-paas.net *.prod.atl-paas.net fonts.googleapis.com *.googletagmanager.com sourcetreeapp.com *.sourcetreeapp.com 'unsafe-inline'; img-src 'self' blob: data: atlassian.com *.atlassian.com *.cookielaw.org *.gravatar.com *.wp.com fd-assets.prod.atl-paas.net pixel.pointmediatracker.com *.prod.public.atl-paas.net cnv.event.prod.bidr.io *.doubleclick.net *.clicktale.net *.bing.com rlcdn.com reddit.com quora.com *.rlcdn.com *.reddit.com *.quora.com *.ctfassets.net *.linkedin.com *.google.com *.google.com.au *.company-target.com *.facebook.com *.google-analytics.com *.twitter.com t.co *.intercomcdn.com *.intercomassets.com *.frontend.public.atl-paas.net *.orangelogic.com *.googletagmanager.com img.logo.dev *.atlassian.net sourcetreeapp.com *.sourcetreeapp.com; font-src 'self' *.ctfassets.net *.intercomcdn.com *.gstatic.com *.frontend.public.atl-paas.net; frame-ancestors 'none'; form-action 'self'; report-uri https://web-security-reports.services.atlassian.com/csp-report/wac-web; report-to csp-default-endpoint; connect-src 'self' ws: atlassian.com *.atlassian.com *.cookielaw.org *.onetrust.com *.public.atl-paas.net *.prod.atl-paas.net *.mktoresp.com *.ingest.sentry.io *.workato.com atlassian.sjv.io statsigapi.net *.statsigapi.net *.contentful.com atlassian.net *.clicktale.net *.contentsquare.net *.bing.com google-analytics.com company-target.com linkedin.com *.google-analytics.com *.company-target.com *.linkedin.com *.doubleclick.net *.reddit.com *.redditstatic.com *.google.com *.demandbase.com *.clarity.ms *.clearbit.com *.intercom.io *.algolianet.com *.algolia.net *.algolia.io *.recaptcha.net https://unpkg.com/@rive-app/ *.facebook.com *.orangelogic.com *.adnxs.com *.6sc.co *.6sense.com apis.auxia.io *.atlassian.net https://participant.connect.us-east-1.amazonaws.com wss://participant.connect.us-east-1.amazonaws.com *.connect.us-east-1.amazonaws.com sourcetreeapp.com *.sourcetreeapp.com; worker-src 'self' blob:; frame-src 'self' *.youtube.com *.google.com *.doubleclick.net *.recaptcha.net *.atl-paas.net *.company-target.com *.googletagmanager.com *.atlassian.net; media-src 'self' *.ctfassets.net *.atlassian.com *.orangelogic.com
content-security-policy-report-only
content-typetext/html
dateFri, 24 Apr 2026 15:35:43 GMT
nel{"failure_fraction": 0.01, "include_subdomains": true, "max_age": 600, "report_to": "endpoint-1"}
report-to{"endpoints": [{"url": "https://dz8aopenkvv6s.cloudfront.net"}], "group": "endpoint-1", "include_subdomains": true, "max_age": 600}
reporting-endpointscsp-default-endpoint="https://web-security-reports.services.atlassian.com/csp-report/wac-web"
serverAtlassianEdge
server-timingcdn-cache-hit,cdn-pop;desc="IAD55-P7",cdn-rid;desc="7J0qTQC9Z5Gq3uJP9IFt2ajEIr26svHpnd9QZ3u51rwrxzoo6b6H-A==",cdn-hit-layer;desc="REC",cdn-downstream-fbl;dur=42
set-cookieajs_anonymous_id=%224f2040c5-65f0-400d-b0b1-5434359e87c3%22; Max-Age=31536000; Path=/; Domain=.atlassian.com;
strict-transport-securitymax-age=63072000; preload
varyAccept-Encoding
via1.1 2f2d826c16934c22388c7129474b7d96.cloudfront.net (CloudFront)
x-amz-cf-id7J0qTQC9Z5Gq3uJP9IFt2ajEIr26svHpnd9QZ3u51rwrxzoo6b6H-A==
x-amz-cf-popIAD55-P7
x-cacheHit from cloudfront
x-content-type-optionsnosniff
x-frame-optionsDENY
x-instance-typer8g.12xlarge
x-node-architecturearm64
x-xss-protection1; mode=block
Related
HTTP Headers for atlassian.com — AtlassianEdge | ProfileMyIP