HTTP Response Headers Inspector
Check HTTP status codes (200, 301, 404), server technologies, compression, and security headers (CSP, HSTS).
HTTP Response for gitlab.com
HTTP/1.1 200 OK| Header Field | Value |
|---|---|
| Status | HTTP/1.1 200 OK |
| Date | Tue, 06 Oct 2026 14:55:25 GMT, Tue, 06 Oct 2026 14:55:25 GMT |
| Content-Type | text/html; charset=utf-8, text/html |
| Content-Length | 0 |
| Connection | close, close |
| Location | https://about.gitlab.com/ |
| CF-Ray | a46581c36ee154ea-DEL |
| CF-Cache-Status | BYPASS, HIT |
| Cache-Control | no-store, public, max-age=0, must-revalidate |
| Server | cloudflare, cloudflare |
| Strict-Transport-Security | max-age=31536000, max-age=31536000 |
| content-security-policy | base-uri 'self'; child-src https://www.google.com/recaptcha/ https://www.recaptcha.net/ https://www.googletagmanager.com/ns.html https://*.zuora.com/apps/PublicHostedPageLite.do https://gitlab.com/admin/ https://gitlab.com/assets/ https://gitlab.com/-/speedscope/index.html https://gitlab.com/-/sandbox/ 'self' https://gitlab.com/assets/ blob: data:; connect-src 'self' https://gitlab.com wss://gitlab.com https://sentry.gitlab.net https://new-sentry.gitlab.net https://customers.gitlab.com https://snowplow.trx.gitlab.net https://sourcegraph.com https://collector.prd-278964.gl-product-analytics.com https://analytics.gitlab.com snowplowprd.trx.gitlab.net; default-src 'self'; font-src 'self'; form-action 'self' https: http:; frame-ancestors 'self'; frame-src https://www.google.com/recaptcha/ https://www.recaptcha.net/ https://www.googletagmanager.com/ns.html https://*.zuora.com/apps/PublicHostedPageLite.do https://gitlab.com/admin/ https://gitlab.com/assets/ https://gitlab.com/-/speedscope/index.html https://gitlab.com/-/sandbox/; img-src 'self' data: blob: http: https:; manifest-src 'self'; media-src 'self' data: blob: http: https:; object-src 'none'; report-uri https://new-sentry.gitlab.net/api/4/security/?sentry_key=f5573e26de8f4293b285e556c35dfd6e&sentry_environment=gprd; script-src 'strict-dynamic' 'self' 'unsafe-inline' 'unsafe-eval' https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://www.recaptcha.net/ https://apis.google.com https://*.zuora.com/apps/PublicHostedPageLite.do 'nonce-AX/RLFBA4p9IWVMCmgZUEA=='; style-src 'self' 'unsafe-inline'; worker-src 'self' https://gitlab.com/assets/ blob: data: |
| gitlab-lb | haproxy-main-50-lb-gprd |
| gitlab-sv | web-gke-us-east1-c |
| nel | {"max_age": 0} |
| permissions-policy | interest-cohort=() |
| ratelimit-limit | 500 |
| ratelimit-name | throttle_unauthenticated_web |
| ratelimit-observed | 1 |
| ratelimit-remaining | 499 |
| ratelimit-reset | 1791298560 |
| referrer-policy | strict-origin-when-cross-origin |
| x-content-type-options | nosniff |
| x-frame-options | SAMEORIGIN |
| x-gitlab-meta | {"correlation_id":"a46581c36ee154ea-DEL","version":"1"} |
| x-permitted-cross-domain-policies | none |
| x-request-id | a46581c36ee154ea-DEL |
| x-runtime | 0.037469 |
| x-ua-compatible | IE=edge |
| x-xss-protection | 1; mode=block |
| ETag | "78f825899aea470df8f85fe1e1cfbb45" |
| CF-RAY | a46581cafe2ab237-DEL |
| alt-svc | h3=":443"; ma=86400 |