HTTP Headers for steampowered.com

Responds with HTTP 200 from nginx — 3 of 6 security headers present.

Domain to Check
200 https://store.steampowered.com/
Security Headers3/6
HSTS
CSP
X-Frame-Options
X-Content-Type-Options
Referrer-Policy
Permissions-Policy
All Response Headers (13)
cache-controlno-cache
connectionclose
content-encodinggzip
content-length0
content-security-policydefault-src blob: data: https: 'unsafe-inline' 'unsafe-eval'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://store.akamai.steamstatic.com/ https://store.akamai.steamstatic.com/ https://recaptcha.net https://www.google.com/recaptcha/ https://www.gstatic.cn/recaptcha/ https://www.gstatic.com/recaptcha/ https://www.youtube.com/ https://s.ytimg.com https://steamcommunity-a.akamaihd.net; object-src 'none'; connect-src 'self' http://store.steampowered.com https://store.steampowered.com http://127.0.0.1:27060 ws://127.0.0.1:27060 https://community.akamai.steamstatic.com/ https://steamcommunity.com/ https://steamcommunity.com/ wss://community.steam-api.com/websocket/ https://api.steampowered.com/ https://login.steampowered.com/ https://help.steampowered.com/ https://steam.tv/ https://shared.akamai.steamstatic.com/ https://checkout.steampowered.com/ https://*.steamstatic.com https://*.steamcontent.com https://*.valvesoftware.com https://*.steambeta.net https://*.discovery.beta.steamserver.net https://*.cqloud.com https://steambroadcast.akamaized.net https://steambroadcast-test.akamaized.net https://broadcast.st.dl.eccdnx.com https://lv.queniujq.cn https://steambroadcastchat.akamaized.net https://api.steampowered.com https://steamvideo-a.akamaihd.net https://video.st.dl.eccdnx.com https://vd.queniujq.cn https://video.cdn.steamchina.eccdnx.com https://video.cdn.queniuqe.com https://video.cdn.steamchina.queniuam.com https://*.storage.googleapis.com; frame-src 'self' steam: http://www.youtube.com https://www.youtube.com https://www.youtube-nocookie.com https://www.google.com https://sketchfab.com https://player.vimeo.com https://steamcommunity.com/ https://login.steampowered.com/ https://help.steampowered.com/ https://checkout.steampowered.com/ https://www.google.com/recaptcha/ https://recaptcha.net/recaptcha/ https://steamcommunity.com/; frame-ancestors 'none';
content-typetext/html; charset=UTF-8
dateFri, 24 Apr 2026 12:53:31 GMT
expiresMon, 26 Jul 1997 05:00:00 GMT
servernginx
set-cookiesessionid=be6165365d69fef19e3df034; Path=/; Secure; SameSite=None
strict-transport-securitymax-age=63072000
varyAccept-Encoding
x-frame-optionsDENY
Related