HTTP Headers for ebay.com

Responds with HTTP 200 OK from ebay-proxy-server — 3 of 6 security headers present.

URL to Check
200 OKhttps://www.ebay.com/
Security Headers3/6
HSTS
CSP
X-Frame-Options
X-Content-Type-Options
Referrer-Policy
Permissions-Policy
All Response Headers (14)
accept-chsec-ch-ua-model,sec-ch-ua-full-version,sec-ch-ua-platform-version
connectionclose
content-length0
content-security-policy-report-onlystyle-src 'self' 'unsafe-inline' data: *.ebay.com *.ebaystatic.com *.ebaystatic.cn *.gstatic.com *.fontawesome.com blob: *.googleapis.com; connect-src 'self' *.ebay.com *.ebaystatic.com *.ebaystatic.cn data: *.google-analytics.com *.doubleclick.net *.avalon.perfdrive.com *.ebayimg.com *.ucweb.com *.akamaihd.net *.ucads.ucweb.com *.analytics.google.com *.g.doubleclick.net *.googletagmanager.com *.pinterest.com *.snapchat.com *.criteo.com *.facebook.com *.googleapis.com *.googleadservices.com blob: analytics.google.com *.us.shoplive.cloud www.facebook.com *.bing.com www.googletagmanager.com google.com *.google.com *.graphitevault.com *.amplitude.com wss://127.0.0.1:* www.redditstatic.com *.reddit.com *.quantummetric.com; script-src 'self' 'unsafe-eval' 'unsafe-inline' https://* blob: data:; frame-ancestors 'self' *.ebay.com *.ebaystatic.com *.ebaystatic.cn; img-src 'self' data: blob: https://*; default-src 'self' blob: data: wss: mediastream: https://*; report-uri https://monitor.ebay.com/csp-report/discoveryplatformweb/HomePage?id=2939504940913871808&rid=t6gludlscuzujfwciunrce00%3C%3Dgludlscuzujfwciunrce00%2Bc7f2%3Faa30.qctp6%3E*m2mv%60-19dbef63a7c-0x2304#pd
content-typetext/html;charset=UTF-8
dateFri, 24 Apr 2026 10:08:21 GMT
rlogidt6qjssfcjb%7B7%3C%3Dqjssfcjb%7B7%2B1a%3C%3F%3F60236(rbpv40.ub0%60k-19dbef63a5c-0x302
serverebay-proxy-server
set-cookie__deba=aD6okqJuLr1a8qPN212MSdAgsvufqYg08ldlQQBwFVh40HAfq-HzcYMTUCbxxb0NXR8UW1J2_XMwSXzXGqPFGDzYw11vCStyngHceo0KKzlrhDxbxjII6kM_3umNaHh60EfWgBpYK3Ls67FVp1CvTw==; HttpOnly; Secure; Path=/; Domain=.ebay.com; Expires=Wed, 21 Oct 2026 10:08:21 UTC
strict-transport-securitymax-age=31536000
x-content-type-optionsnosniff
x-envoy-upstream-service-time229
x-frame-optionsSAMEORIGIN
x-xss-protection1; mode=block
Related
HTTP Headers for ebay.com — ebay-proxy-server | ProfileMyIP