Security Report Summary
D
Site: | https://www.qatarairways.com/en-ie/homepage.html | ||
---|---|---|---|
IP Address: | 23.72.34.166 | ||
Report Time: | 26 Aug 2025 19:55:54 UTC | ||
Headers: |
|
||
Advanced: |
|
Missing Headers
Content-Security-Policy | Content Security Policy is an effective measure to protect your site from XSS attacks. By whitelisting sources of approved content, you can prevent the browser from loading malicious assets. |
---|---|
Referrer-Policy | Referrer Policy is a new header that allows a site to control how much information the browser includes with navigations away from a document and should be set by all sites. |
Permissions-Policy | Permissions Policy is a new header that allows a site to control which features and APIs can be used in the browser. |
Warnings
Strict-Transport-Security | The "max-age" directive is too small. The minimum recommended value is 2592000 (30 days). |
---|
Raw Headers
HTTP/2 | 200 |
---|---|
server | Apache |
x-content-type-options | nosniff |
x-xss-protection | 1 |
accept-ranges | bytes |
vary | Accept-Encoding |
access-control-allow-headers | Accept,traceparent,Request-Id,Content-Type,User-Agent |
content-type | text/html; charset=UTF-8 |
x-akamai-transformed | 9 - 0 pmb=mTOE,2mRUM,2 |
content-encoding | gzip |
date | Tue, 26 Aug 2025 19:55:53 GMT |
set-cookie | AKA_A2=A; expires=Tue, 26-Aug-2025 20:55:53 GMT; path=/; domain=qatarairways.com; secure; HttpOnly |
server-timing | cdn-cache; desc=HIT |
server-timing | edge; dur=1 |
x-frame-options | SAMEORIGIN |
strict-transport-security | max-age=86400 |
set-cookie | bm_ss=ab8e18ef4e; Secure; SameSite=None; Domain=.qatarairways.com; Path=/; HttpOnly; Max-Age=3600 |
set-cookie | _abck=D4277594DC18055E8AEFE2C32BAF5A05~-1~YAAQpiVIFzqTZ+OYAQAA04jz5w4aP5z7wxaW7iBl5iYtTJfKec3z/YiRdptzsgOmBrrGQKUtqXqWwbIqjr5fyGHCr9k9ncjM4wjzhUVdy+jdL6s7SkEYxBBo35ixBkks4GZaccB5oV9JRxNGVNBbdtR9PCoO/j3vtoygyGNcM9OKjg8AIsffgRiMX2TBdup+KWJnXlFQXJpZZwNMIZgslKq3kbgpifWm3p/QJaLqQiPtCExo8sPfSsaGQoxhM2995GDWqiSQhYON9YkRXvP26RBLc7J6hjPCAPxGmqglUq97FdaJTcH/rZ0gfC5SnQoOycl3UwOtE5ymqN96eW5PstAzG+lmkqoU27E3Uwjpdml3MEolxPmAfwDw+mpz4uJcDcmn6vb4dDvYN9ER6lgJD9B54zANEpM5VWNyr1hkkM5KKvDxmoMBgF8Kf28N4LdjuVlfeY/ua9zIMhSYj0o=~-1~-1~-1~~; Domain=.qatarairways.com; Path=/; Expires=Wed, 26 Aug 2026 19:55:53 GMT; Max-Age=31536000; Secure |
set-cookie | ak_bmsc=89AFF57CF7159451BEAEABD8A53E7590~000000000000000000000000000000~YAAQpiVIFzuTZ+OYAQAA04jz5xwor5bki72IDxNb/9TogunvYKtq+BHa5TUeygEvVpxp8NShgQWUYekijgOpqtvUTkbQQns0teNAzcm35AP1EYdjx4se0doHyQW3bvhsH/S6HKf/vOPTEedNYPEoEw+nU8A2CXBDsgFzT7oc+KBEr/2t9fFoP/JzwpDDrmuNzxEew3y23towK1+awAnPaSji2QlcwgTI0mzLs54kthLnTsUYJMXI8ZDSyWrxBKwk4Ni4y8GTzuEo90sQI9BRcdBH08+FvHk19QwUXl8a5C/A5IRAGosq808dvdtBsWy4+kc0FsURBlDfGA3Uh1Z3eFknO1Bu5ixbcP7IQOt54YDWXQ0EhNNZgnGJ4rY2VqJMrchckp5kVsxi67E4HzMNEc5nRA==; Domain=.qatarairways.com; Path=/; Expires=Tue, 26 Aug 2025 21:55:53 GMT; Max-Age=7200 |
set-cookie | bm_mi=07A421F7DEE2A80B6890037A1DD1ADA0~YAAQpiVIFzyTZ+OYAQAA04jz5xz1RwSBR4HqvrJLjkEk9MQQ4h7hqgqxaRsVtQy2FJrLP4Glp/W8f4jiiU6t8Lw4x0Dx5/ejX6Pj7RdC2Kdv1wjeKF+8sTxo6llHL1hdmbZAXzLHP5N200Ke+yREKqs+j+0Ow1DoC3ONeUFHtelx9fMdCzl8BYVHhD+psn0yfFA2AscLjc+moeyYF6NppeUg28M7GSA8EvLr6jvKU3wW/tO9xw681N/AIpWNwVOhIuhgPGXGoNdx/cbl9DTbkPejQV+AM1Q/Xpr1E1MoP6GMrXkSbQ6KPzYx/oTHFGhzaUZ4xVRAs7fuyx2wDY2wIWgF/vE6xQc=~1; Domain=.qatarairways.com; Path=/; Expires=Tue, 26 Aug 2025 19:55:53 GMT; Max-Age=0; Secure |
set-cookie | bm_s=YAAQpiVIFz2TZ+OYAQAA04jz5wMqG8GEBBNq+nW5QCCxh55cZzriKejvuhtVcUTn8wMWUX8e5N3mN7ts8CgpWQnmS0EaZRVKHqlZxgBTQ/XMrtq30HVm3owELIVPK8E3QGmqKK7n9Gba7SSm45oyXYI3RezASavaSaXRYjb+W7eFwcxJfD4xNKGgRBW9pNz0u9245BR5WjgR2dC7HT2EP1VBO013RQpxOxWySiV9CC2USzu3Nhk6XPJ6ZjCKcTtEn+H8nQyAaE/NQwY8CO3o8mcjO180a1ti36YcBKCeglZ/OzVwJBljEOcTpheCGYDjCXvXRGXbw13KAR4PhhNYGLIGzAQ7zonbYDCRgAbervkvR6axRlnuaC49Qyh3qKSKu7PlNeNP7aGMRkACadFnCKYJ8Mtuaj3X8uBkmXR0/i/Kqirc84dBqsZZhOwyuFTDaz9jdQiyUO+TqIAFj6OqxVC0M7L+GrPliUsLpQ813DeP0ov10zJLuNBxPjh4XPe34hpKKl2S0T2Klnq09EK5gVEjAh0kupdejQQmkzzZpxJLE5HFMPadbiXtH9YR; Domain=.qatarairways.com; Path=/; Expires=Fri, 26 Sep 2025 19:55:53 GMT; Max-Age=2678400; Secure; HttpOnly |
set-cookie | bm_so=1C87AE6F132CD969E60605372B0B9EECF8034BA7112F6FF1C3BEC064F29E0A44~YAAQpiVIFz6TZ+OYAQAA04jz5wQhJZw1IuwF7+0a3YPypk2Lf1bo5wMMwEuz4ltUX5WEavd/7Gr4mS58GoBMGnM0yxSIBVcCD3MHhZS/3dPLHWGBNmAtVskM0YITQxZG0JWNVmU0D5koSz8oTfiFWcFBxs4ATdqcni0LcrEm1DPkFQRbVdR7Eno+io39aPfI/z5CEQZQP0K/GkuMznY5g4rU2wEnF2qCGnR7/IbyWGu6xfTJQF4n+/99ZCz6ppAaTvq97kHp9/0APYczKgoAwTszv2SBktzw0PZKKqVziAvVFof/fzZfP85sxFuLI2sRpmYw1RjRB7Xd4vr+K/RsAbKpMpsGbxW1djqhWYnJLEXdUhq7u2PM3ihIdcDd1KzLScJduxTwHQ/UF0FL2yR9iotFrp68E94BTWv7pc1zk6vbc0Di/lul5e4JwQ4/3hgxvbI5mIm7xmjL6ujV1L11W/GPXCjB; Domain=.qatarairways.com; Path=/; Expires=Wed, 27 Aug 2025 19:55:53 GMT; Max-Age=86400; Secure |
set-cookie | bm_sz=2D2E2D96D0BD3C33970EAA8582CD93BB~YAAQpiVIFz+TZ+OYAQAA04jz5xzyEBTV7yUzP9jfMoq4gyYhREtIiwNNVOvZd5R5ha5LE/+EvbLKXRD/iVQa6Rwi7eGmEcVhUn0s8YzseR/8bwaQrjcOrmH1WOszHnJDcX5iSn0WllSJqfheCKw/RtBkSM6xvsuH8D/jtgOziqsdh3FQTKVs/tmsofXyjEca3SO/kVJ8KRH47SSntN1pZi4UkaPvjDn/+x7/qZ1sOh79wOF6o66DvbZ6hlvhtMEec09Qj2Ct7bmdeLSuyQrspRx5UrSeju+/ZCIPPhB98nZ/Zt9sins/8GIEliVc/H5sAhhmUw2ilvu9FHuHalFBdaZF+AmTBDNM8qKe2Ez2xq4sJxDPhmuzkXv67CbxSZXA5cQ36l6UPVudKn8QKYdyTwYxtTY=~3158580~3356977; Domain=.qatarairways.com; Path=/; Expires=Tue, 26 Aug 2025 23:55:53 GMT; Max-Age=14400 |
server-timing | ak_p; desc="1756238153838_390604198_137103614_92_14956_4_4_15";dur=1 |
Upcoming Headers
Cross-Origin-Embedder-Policy | Cross-Origin Embedder Policy allows a site to prevent assets being loaded that do not grant permission to load them via CORS or CORP. |
---|---|
Cross-Origin-Opener-Policy | Cross-Origin Opener Policy allows a site to opt-in to Cross-Origin Isolation in the browser. |
Cross-Origin-Resource-Policy | Cross-Origin Resource Policy allows a resource owner to specify who can load the resource. |
Additional Information
server | This Server header seems to advertise the software being run on the server but you can remove or change this value. |
---|---|
x-content-type-options | X-Content-Type-Options stops a browser from trying to MIME-sniff the content type and forces it to stick with the declared content-type. The only valid value for this header is "X-Content-Type-Options: nosniff". |
x-xss-protection | X-XSS-Protection sets the configuration for the XSS Auditor built into older browsers. The recommended value was "X-XSS-Protection: 1; mode=block" but you should now look at Content Security Policy instead. |
x-frame-options | X-Frame-Options tells the browser whether you want to allow your site to be framed or not. By preventing a browser from framing your site you can defend against attacks like clickjacking. |
strict-transport-security | HTTP Strict Transport Security is an excellent feature to support on your site and strengthens your implementation of TLS by getting the User Agent to enforce the use of HTTPS. |