Security Report Summary
C
Site: | https://www.autodesk.com/fr | ||
---|---|---|---|
IP Address: | 23.72.33.216 | ||
Report Time: | 06 Sep 2025 23:26:12 UTC | ||
Headers: |
|
||
Advanced: |
|
Missing Headers
Content-Security-Policy | Content Security Policy is an effective measure to protect your site from XSS attacks. By whitelisting sources of approved content, you can prevent the browser from loading malicious assets. |
---|---|
Referrer-Policy | Referrer Policy is a new header that allows a site to control how much information the browser includes with navigations away from a document and should be set by all sites. |
Permissions-Policy | Permissions Policy is a new header that allows a site to control which features and APIs can be used in the browser. |
Raw Headers
HTTP/2 | 200 |
---|---|
content-type | text/html; charset=UTF-8 |
server | Apache |
serverid | dotcom-prd-web-publish01-ue1 |
last-modified | Sat, 06 Sep 2025 23:26:11 GMT |
etag | W/"59f88-63e2a47ad6b20:dtagent10319250807130352LL9n" |
accept-ranges | bytes |
x-oneagent-js-injection | true |
x-ruxit-js-agent | true |
server-timing | dtSInfo;desc="0", dtRpid;desc="345232757" |
x-akamai-transformed | 9 - 0 pmb=mTOE,4 |
content-encoding | gzip |
expires | Sat, 06 Sep 2025 23:26:12 GMT |
cache-control | max-age=0, no-cache, no-store |
pragma | no-cache |
date | Sat, 06 Sep 2025 23:26:12 GMT |
vary | Accept-Encoding |
set-cookie | AWSALBTG=10sDetK6CoOKzAmqyuZFLzKs9RgjBr0DrFn+F0EkNRCUmkjd5qgk09tH+utNZPFV2hMN4jrEQFEgKkheopQ5d//6xe9FKevqkENj2kwp7QijE5DiH1U/hMUVV8cg3Cv+TqFk8u1Z4ZweKPvaqqu9C6Sty4TInKi4MUSTjahTruN8XEfWZJg=; Expires=Sat, 13 Sep 2025 23:26:11 GMT; Path=/ |
set-cookie | AWSALBTGCORS=10sDetK6CoOKzAmqyuZFLzKs9RgjBr0DrFn+F0EkNRCUmkjd5qgk09tH+utNZPFV2hMN4jrEQFEgKkheopQ5d//6xe9FKevqkENj2kwp7QijE5DiH1U/hMUVV8cg3Cv+TqFk8u1Z4ZweKPvaqqu9C6Sty4TInKi4MUSTjahTruN8XEfWZJg=; Expires=Sat, 13 Sep 2025 23:26:11 GMT; Path=/; SameSite=None; Secure |
set-cookie | AWSALB=+Lyr71ztQhfbTg3GWx+KKiV7bAKsntD2hkoPgsFj22pzON/189IuRNinRg5ATRIJQ94BoPHmy8okSw9oqrj5yLV8AjO4F1WaXg1gWiAgmCoq+350Uug5BxE8yzz1; Expires=Sat, 13 Sep 2025 23:26:11 GMT; Path=/ |
set-cookie | AWSALBCORS=+Lyr71ztQhfbTg3GWx+KKiV7bAKsntD2hkoPgsFj22pzON/189IuRNinRg5ATRIJQ94BoPHmy8okSw9oqrj5yLV8AjO4F1WaXg1gWiAgmCoq+350Uug5BxE8yzz1; Expires=Sat, 13 Sep 2025 23:26:11 GMT; Path=/; SameSite=None; Secure |
set-cookie | dtCookie=v_4_srv_3_sn_222C98997C9FCD1222008F7D31BB076B_perc_100000_ol_0_mul_1_app-3A5e4183b07b9fbcb4_1; Path=/; Domain=.autodesk.com |
set-cookie | cdn-user-cc=IE |
alt-svc | h3=":443"; ma=93600 |
akamai-request-bc | [a=23.72.36.215,b=2489757343,c=g,n=IE__DUBLIN,o=20940],[c=c,n=GB_EN_LONDON,o=20940],[a=144,c=o] |
timing-allow-origin | * |
x-frame-options | SAMEORIGIN |
x-xss-protection | 1 |
x-content-type-options | nosniff |
strict-transport-security | max-age=31536000 |
akamai-cache-status | Miss from child, Miss from parent |
akamai-grn | 0.d7244817.1757201171.9466ae9f |
set-cookie | _abck=DEAC73E9130645B37B10BECEADEE3466~-1~YAAQ1yRIFy9fy9SYAQAAAwhaIQ7nYSjFwQQ1CYBWwdsk1gSj7jMf5klgEZVNZcKPLxOUPBRu+ls71XaQJZNyAUtSVi8wDWofyZtQphM6PIXpfjygMvti3Gap1fXPYKPQ1E1yFOip6yNh8Hk8I0/EdgPcYBZq3MRpvoAWvHUJstCoAQvJec31kcfFu3tqj+vta72OcwSGeJB66udAF2FkRwP6Nw8ehfEVlrQglA3mwJYwO9CR1mPvHcx/R5g0TiXpx2D46IdtcuofSOPpPfYxhymjrooeYj5Pgiy7xGk6/6aAi5/GekcrH87N6kNFKdI2Gi/g2ERM/eieyuZhQGQzUvO36aQzbJftX/39TwtVFkjxSiXBiu0p27J01WzfahoNbJnkU/5aeA4Y8eB1XlSMdiQOScQWaIGlXtvcGOpXyS2QYALZA58VMXHgTkVc0n3IebppJegQRVpIZw==~-1~-1~-1~~; Domain=.autodesk.com; Path=/; Expires=Sun, 06 Sep 2026 23:26:12 GMT; Max-Age=31536000; Secure |
set-cookie | ak_bmsc=434BD130F3F1EC34DE4143E20FEAF24A~000000000000000000000000000000~YAAQ1yRIFzBfy9SYAQAAAwhaIR0Qb1Dh/UbXF+9EgadAwIxq1BLX63RwXB3RlDhGdGILQOKvRFAWyohAOKemy0cA2q8P2qoJAtFYTIMUyHLOz4N3H36JifxZk/9KsG0WtYxzRnfRgOVXgsfA9HF6SlcJw20SWl87G1po4JEVxjYrH7I0xHepWPJ/JzqtozN19MhuOlkTnpumbPRVsbr0qtW+p66CMc9ZjHKMaYWRRkaUreGlvxYYhh1FNv6zetgmfRoMwkzblBpBQfR/OZNXpSPs3zczSrORzzUyQzgS4+D8JmIJMQTT9KbeitwA9uM9AsQFlsJMbO5STgeGPOHgzBzUEgQ5kpcydiClrMOpQfaT8NKwBBpIlAPrHy8WARqjoFoJiz/IXBBEy4xtlBf7; Domain=.autodesk.com; Path=/; Expires=Sun, 07 Sep 2025 01:26:11 GMT; Max-Age=7199 |
set-cookie | bm_mi=F1252F741ED824E84ED398410F18BFA0~YAAQ1yRIFzFfy9SYAQAAAwhaIR1eHkP6kZjnybj2mRnXnNrgyIK/RBcj6pGQ2r9Q6V6UHiRTEmRL47cTedgcCiok+2uboZO/H1VY6UlwWT+9rSWQpQlX8UMHYuMdvGa/VGsCur9wO7GLRWijDBbQDBquprl1XVuAF4FT7u6Cm6uQhBk7Zi2QKMSi2fir3vSpYHh19QtSZGOdbuX4QqJvL9CEa0M8wKC+U+UoD5MbuYSLS1VUUWgzrWQ157Ot8x482JMYhRwpGq9wyRTvvCkj3SwPDOpOWI9TBuKmVrt4Bnm2vITN4AtocoCpLB4FkLDuwq0=~1; Domain=.autodesk.com; Path=/; Expires=Sat, 06 Sep 2025 23:26:12 GMT; Max-Age=0; Secure |
set-cookie | bm_sz=7E63435F96533D4808D6DC3B0829FDAB~YAAQ1yRIFzJfy9SYAQAABAhaIR1WzJuRlAc3+YsqtIpDAW506BZ/jzOzS6dc/ZajDp1MTmonMWkkkgIszJEjkbjVU7gwVeWtOIMcE4wg2fUqw6o4WKXZbgM6ptOJZa9YdATUEDfSFeWNAY+GLT7zlHLxlNXom4TdUvgcfB/CK2wzlpM6aznWY9ynT0diX/NXZKOutRYCFHjUyCdUl5eexeWYFEpnreHgx13JRyWqv7j3eiWts2GUKFav5mdcss8FL2SmZqq/EL9vOQ7iN99UQe5+pdwi5wXYWrg11TB3uj29FV3j2s++LQA8wJmqC4lIYuLZIVcs6x2VRNQ1S2CUh90JWdWSAutINH0lMYPNSmvWJzXsxk2wHV3U/h8vR8kCTMM9whePd9ZokZi8FNO4zr8=~4340033~3621937; Domain=.autodesk.com; Path=/; Expires=Sun, 07 Sep 2025 03:26:11 GMT; Max-Age=14399 |
Upcoming Headers
Cross-Origin-Embedder-Policy | Cross-Origin Embedder Policy allows a site to prevent assets being loaded that do not grant permission to load them via CORS or CORP. |
---|---|
Cross-Origin-Opener-Policy | Cross-Origin Opener Policy allows a site to opt-in to Cross-Origin Isolation in the browser. |
Cross-Origin-Resource-Policy | Cross-Origin Resource Policy allows a resource owner to specify who can load the resource. |
Additional Information
server | This Server header seems to advertise the software being run on the server but you can remove or change this value. |
---|---|
x-frame-options | X-Frame-Options tells the browser whether you want to allow your site to be framed or not. By preventing a browser from framing your site you can defend against attacks like clickjacking. |
x-xss-protection | X-XSS-Protection sets the configuration for the XSS Auditor built into older browsers. The recommended value was "X-XSS-Protection: 1; mode=block" but you should now look at Content Security Policy instead. |
x-content-type-options | X-Content-Type-Options stops a browser from trying to MIME-sniff the content type and forces it to stick with the declared content-type. The only valid value for this header is "X-Content-Type-Options: nosniff". |
strict-transport-security | HTTP Strict Transport Security is an excellent feature to support on your site and strengthens your implementation of TLS by getting the User Agent to enforce the use of HTTPS. |