HTTP Headers for expedia.com

Responds with HTTP 429 Too Many Requests from istio-envoy — 4 of 6 security headers present.

Domain to Check
429 Too Many Requestshttps://www.expedia.com/
Security Headers4/6
HSTS
CSP
X-Frame-Options
X-Content-Type-Options
Referrer-Policy
Permissions-Policy
All Response Headers (26)
akamai-request-bc[a=2.17.114.154,b=3555936498,c=g,n=US_VA_CHANTILLY,o=20940],[c=c,n=US_VA_ASHBURN,o=20940],[a=208,c=o]
cache-controlno-cache, no-store, must-revalidate
connectionclose
content-languageen-US
content-length0
content-security-policyframe-ancestors 'self'
content-typetext/html; charset=utf-8
ctx-view-idd7203168-3a4c-4d3b-910a-ff5d8cc16693
dateFri, 24 Apr 2026 15:43:03 GMT
serveristio-envoy
set-cookiebm_sz=2248770FD8B789B3F5E1823A399113F8~YAAQmnIRArzl9ZKdAQAAaqgowB9STREhOJ46VDqoLXv81NiNKRIfFB3wtGRagX80fgalQfbuAof0lT/+G+Vmxrns7fr2owFFrGmc4Nflia40vag0Mmr83Wk8iJRNE8W4Z6Gn6xUtsDLcNlf3jN889BENCLnutuQtUdF0lNAi2s8z5bTw7eIFj2tXCDDagLiTWBt8D950J9L0o+IDxFUH0ijn5GrjxpgIF25ga9s+psL4JSJYcaDVqwGvz96RKl1X3p2bDBlglDDty3zv3E5bErVbijVKfclWePwuia4LGQIXPiOY7XXHxGZqtkrp9IOa+TTANVJznbRhRXovHxRa3sEbhZcMNUfzRhxfDDGgNQ==~3621174~3360305; Domain=.expedia.com; Path=/; Expires=Fri, 24 Apr 2026 19:43:03 GMT; Max-Age=14400
strict-transport-securitymax-age=7776000; includeSubDomains;
trace-id56f624aa-078c-4352-8efa-766ead7f602d
varyaccept-encoding
x-akamai-reference-id0.9a721102.1777045383.d3f348f2
x-app-infocaptcha-pwa,dda0792ee4d3868ae6e19b1cd1ef0f8aff76136a
x-b3-traceid56f624aa078c43528efa766ead7f602d
x-cgp-infonoJvmRouteSet;b392845c-a918-4eac-abd1-687b1facd7b5
x-content-type-optionsnosniff
x-download-optionsnoopen
x-envoy-upstream-service-time15
x-frame-optionsSAMEORIGIN
x-hcom-origin-idwildcard-challenge-handler
x-page-idwildcard-challenge-handler
x-permitted-cross-domain-policiesnone
x-xss-protection1
Related
HTTP Headers for expedia.com — istio-envoy | ProfileMyIP