Missing Headers
Content-Security-PolicyContent Security Policy is an effective measure to protect your site from XSS attacks. By whitelisting sources of approved content, you can prevent the browser from loading malicious assets.
Referrer-PolicyReferrer Policy is a new header that allows a site to control how much information the browser includes with navigations away from a document and should be set by all sites.
Permissions-PolicyPermissions Policy is a new header that allows a site to control which features and APIs can be used in the browser.
Raw Headers
HTTP/1.1200 OK
Cache-Controlno-store, must-revalidate, no-cache
Content-Typetext/html; charset=utf-8
Content-Encodinggzip
Expires-1
VaryAccept-Encoding
x-ms-gateway-requestiddf792b04-0f0a-45d3-b0d3-ab006df3dd5a
X-UA-CompatibleIE=edge
X-Request-ID06fd5d26-9cd7-4d6b-aed4-0cb2eb02fd14
X-Build1.1.142.0
X-Frame-OptionsDENY
PublicOPTIONS,TRACE,GET,HEAD,POST
Strict-Transport-Securitymax-age=31536000; includeSubDomains
X-Content-Type-Optionsnosniff
X-XSS-Protection1; mode=block
Set-Cookiex-ms-cpim-sso:qalabcapitalb2c.onmicrosoft.com_0=m1.3v8/OJMZmb2WWxxh.Jb2FEpmfYPNOCALIzwx8Ow==.0.ReWpuAKJJ0oNrSyBGgt385jqmJqnU0DgBjL8PEaaDL0B+31iSOx35uKMe62BNAXrhiIRQ3Rr4U3wsb9ATZCs0La+GQM4powqrc8d8PCXxwMSj4DBQLoLwsqMpE3EKLwhjlzlKRPWIqcR8QasoNnRLuGl8yJmomdJOmdf7vjX7LtkisXGxkqFdfibjbq/SX2aPaQNJTMV9cBRxZRWt7/hoduH8+huo5ETf/Dty4CL6TPOwssprQZE21xXkLKHHuHKdgNLrcsbYyvds/mEN3ryIDMSPBbfbq7W/DVZ5ZiLOhS+4aeplIxcNTJYU5Unu51EFYEfZBlcyr4UTX6dUNUu3tY=; domain=qalabcapitalb2c.b2clogin.com; path=/; SameSite=None; secure; HttpOnly
Set-Cookiex-ms-cpim-csrf=a2ZIWkR4cFpaM1FjaTg1SFk0Um9uSFVmWVlSOUt2WkY5bzFEeHoyMkZ3WjBjZXBCNnZUUnZLVmtCd0RmZExkQ3prM1AyUkpueXJ4cWMzY3N1RE5ma0E9PTsyMDI0LTA1LTAyVDEzOjAxOjQyLjA4OTM3MDNaO3Z1bVcyc0llODhheWxrWGhEUEExOWc9PTt7Ik9yY2hlc3RyYXRpb25TdGVwIjoyfQ==; domain=qalabcapitalb2c.b2clogin.com; path=/; SameSite=None; secure; HttpOnly
Set-Cookiex-ms-cpim-cache|jl39bteca02u1ayy6wl9fa_0=m1.gwclMhNFupjkob/v.TpTdaCMMMfbufilAgIB7Dw==.0.G05BZSSwdePtZdr1rGD1zTd9Pv6w3aMK3t5zkgqi+CCPBOZEudWtZF3/Ydcn+0tzudyyZhCR6JwUXFPcgHKv2ngkbQagl6NzWE/4QbsYBTV6qu8n6OCu3uB18hyt/yzcIMJ4jhgUPgwgZLWhy2GPSznB9iHhZDaeRPC1IAh5/HzpyIs0qstJ7YsvAq9KNn8wBAphQM7r8r7BS526cGKt/QVeT3Zh93z0gqs9A40abZOvusQHsxWtDqRdAIUAz5z1R1lmahWdDD2/+RjbKvRvLfCDXj5liQJBDRqqUTqRaao0EzhjSW4bY5+EhLWJ1nIU/4/HI7jaM0XFEebQGkcIDs5lAKQAls0NSefNsZyrNRQWePijqewwStNxbUbfUvutQSb7gR8vJSkzkVjynnz1q1r6AcP4t7fRzhBxAOQYjTeRhdkWzMm9Da2Hx0xTk0v4PmsKdcjidHZX8Uyb9CIlN2DNzm5vcHJ2H4fFKzswNPsydx2Mbh5GIsk81pJZYFGs8wnSpNusYvEgXAZDH8Hi7KdlZ+GJa5zwUARsso3ScSm9z1KuQBhsXwncADbi2QBGmRLyN8L7TJgVph7z+YOTTLjsvS/ZhhwP2a7XlwhW+UNAIDD7sRyzF/fT2s5UpvmpS4qQN2tXqohDFaUvCVjYp8TBSuNv9WImV6QBg//avCpovlzuuAmzs9gih61Rle9p9iZMZ5et8QR90nhOTGDn+tkcG7JMLgwq+tZKYONz1C9RvgMp8YTLPzwYT6K++M2Eky0p7hXyh9OO9Brm0bD8vncowyZBH3ECLOpexTFhvuJ7vbm3YTHDJfuJJqLwXeSrvOFso1+ItSqq42ngJsrrSpUjNARkYQgW7Trzc5Z5WzDmjFeW2rLD3483A0uNLT4TZ2xv5md2tisO8u4OX1WPtZzCJHqo7uTDmjItwpkU6/P7uGU0V0nqHs8xac5RIEEl4FWzfR9UlPPew+qGnxM969iIzJcgT5yZS/X6OUrF5/Bj87qclkAGlQT2FtMPjBmv2X+RIVgP6WAib4IWd8XPZ345nkm0w6VqUbCJXQ1EE6vGbGeSD7VDxCqdgzJnIvcK++BWr4ckxjwvX8RNNC93an2YUz2eLOECig==; domain=qalabcapitalb2c.b2clogin.com; path=/; SameSite=None; secure; HttpOnly
Set-Cookiex-ms-cpim-trans=eyJUX0RJQyI6W3siSSI6IjA2ZmQ1ZDI2LTljZDctNGQ2Yi1hZWQ0LTBjYjJlYjAyZmQxNCIsIlQiOiJxYWxhYmNhcGl0YWxiMmMub25taWNyb3NvZnQuY29tIiwiUCI6ImIyY18xYV90cmFuc2FjY2lvbmFsbm9jYXB0Y2hhX3NpZ25pbiIsIkMiOiI0ZjU1Nzc2My1kYjNlLTQ4MzgtYjczMi0xNWJmMTkwNjdhMzEiLCJTIjoxLCJNIjp7fSwiRCI6MCwiRSI6IiJ9XSwiQ19JRCI6IjA2ZmQ1ZDI2LTljZDctNGQ2Yi1hZWQ0LTBjYjJlYjAyZmQxNCJ9; domain=qalabcapitalb2c.b2clogin.com; path=/; SameSite=None; secure; HttpOnly
AllowOPTIONS
AllowTRACE
AllowGET
AllowHEAD
AllowPOST
DateThu, 02 May 2024 13:01:41 GMT
Content-Length88282
Upcoming Headers
Cross-Origin-Embedder-PolicyCross-Origin Embedder Policy allows a site to prevent assets being loaded that do not grant permission to load them via CORS or CORP.
Cross-Origin-Opener-PolicyCross-Origin Opener Policy allows a site to opt-in to Cross-Origin Isolation in the browser.
Cross-Origin-Resource-PolicyCross-Origin Resource Policy allows a resource owner to specify who can load the resource.
Additional Information
X-Frame-OptionsX-Frame-Options tells the browser whether you want to allow your site to be framed or not. By preventing a browser from framing your site you can defend against attacks like clickjacking.
Strict-Transport-SecurityHTTP Strict Transport Security is an excellent feature to support on your site and strengthens your implementation of TLS by getting the User Agent to enforce the use of HTTPS.
X-Content-Type-OptionsX-Content-Type-Options stops a browser from trying to MIME-sniff the content type and forces it to stick with the declared content-type. The only valid value for this header is "X-Content-Type-Options: nosniff".
X-XSS-ProtectionX-XSS-Protection sets the configuration for the XSS Auditor built into older browsers. The recommended value was "X-XSS-Protection: 1; mode=block" but you should now look at Content Security Policy instead.
Set-CookieThere is no Cookie Prefix on this cookie. This is not a SameSite Cookie.
Set-CookieThere is no Cookie Prefix on this cookie. This is not a SameSite Cookie.
Set-CookieThere is no Cookie Prefix on this cookie. This is not a SameSite Cookie.
Set-CookieThere is no Cookie Prefix on this cookie. This is not a SameSite Cookie.