HTTP Headers for mozilla.org

Responds with HTTP 200 from granian — 5 of 6 security headers present.

Domain to Check
200 https://www.mozilla.org/en-US/
Security Headers5/6
HSTS
CSP
X-Frame-Options
X-Content-Type-Options
Referrer-Policy
Permissions-Policy
All Response Headers (27)
accept-rangesbytes
age582
cache-controlmax-age=600
connectionclose
content-encodingbr
content-languageen-US
content-length19669
content-security-policyframe-src 'self' accounts.firefox.com js.stripe.com www.google-analytics.com www.googletagmanager.com www.youtube.com; script-src 'self' 'unsafe-eval' 'unsafe-inline' cdn.transcend.io js.stripe.com s.ytimg.com tagmanager.google.com transcend-cdn.com www.google-analytics.com www.googletagmanager.com www.mozilla.org www.youtube.com; object-src 'none'; base-uri 'none'; img-src 'self' blog.mozilla.org data: images.ctfassets.net www.google-analytics.com www.googletagmanager.com www.mozilla.org; style-src 'self' 'unsafe-inline' cdn.transcend.io transcend-cdn.com www.mozilla.org; form-action 'self' https://abdri3ttkb.execute-api.us-east-2.amazonaws.com https://accounts.firefox.com/ https://basket.mozilla.org; media-src 'self' assets.mozilla.net videos.cdn.mozilla.net www.mozilla.org; font-src 'self' www.mozilla.org; frame-ancestors 'none'; connect-src 'self' cdn.transcend.io gtm.mozilla.org https://abdri3ttkb.execute-api.us-east-2.amazonaws.com https://accounts.firefox.com/ https://basket.mozilla.org o1069899.ingest.sentry.io o1069899.sentry.io region1.google-analytics.com telemetry.transcend.io telemetry.us.transcend.io transcend-cdn.com www.google-analytics.com www.googletagmanager.com www.mozilla.org/submit/bedrock/; upgrade-insecure-requests; default-src 'self' *.mozilla.org
content-security-policy-report-onlyframe-src 'self' accounts.firefox.com js.stripe.com www.google-analytics.com www.googletagmanager.com www.youtube.com; script-src 'self' 'unsafe-eval' 'unsafe-inline' cdn.transcend.io js.stripe.com s.ytimg.com tagmanager.google.com transcend-cdn.com www.google-analytics.com www.googletagmanager.com www.mozilla.org www.youtube.com; object-src 'none'; base-uri 'none'; img-src 'self' blog.mozilla.org data: images.ctfassets.net www.google-analytics.com www.googletagmanager.com www.mozilla.org; style-src 'self' 'unsafe-inline' cdn.transcend.io transcend-cdn.com www.mozilla.org; form-action 'self' https://abdri3ttkb.execute-api.us-east-2.amazonaws.com https://accounts.firefox.com/ https://basket.mozilla.org; media-src 'self' assets.mozilla.net videos.cdn.mozilla.net www.mozilla.org; font-src 'self' www.mozilla.org; frame-ancestors 'none'; connect-src 'self' cdn.transcend.io gtm.mozilla.org https://abdri3ttkb.execute-api.us-east-2.amazonaws.com https://accounts.firefox.com/ https://basket.mozilla.org o1069899.ingest.sentry.io o1069899.sentry.io region1.google-analytics.com telemetry.transcend.io telemetry.us.transcend.io transcend-cdn.com www.google-analytics.com www.googletagmanager.com www.mozilla.org/submit/bedrock/; upgrade-insecure-requests; default-src 'self' *.mozilla.org
content-typetext/html; charset=utf-8
cross-origin-opener-policysame-origin
dateFri, 24 Apr 2026 14:14:53 GMT
etag"f1c9565dfb697e45536a0d86ef034ffa"
expiresThu, 23 Apr 2026 17:10:04 GMT
referrer-policystrict-origin-when-cross-origin
servergranian
strict-transport-securitymax-age=31536000
varyAccept-Encoding
via1.1 google, 1.1 varnish, 1.1 varnish
x-backend-serverbedrock-78995ffd58-skjfq.gcp-us-west1
x-cacheMISS, HIT
x-cache-hits0, 1
x-clacks-overheadGNU Terry Pratchett
x-content-type-optionsnosniff
x-frame-optionsDENY
x-served-bycache-iad-kcgs7200078-IAD, cache-iad-kjyo7100131-IAD
x-timerS1777040093.117301,VS0,VE2
Related