HTTP Response Headers Inspector
Check HTTP status codes (200, 301, 404), server technologies, compression, and security headers (CSP, HSTS).
HTTP Response for max.com
HTTP/1.1 200 OK| Header Field | Value |
|---|---|
| Status | HTTP/1.1 200 OK |
| Server | CloudFront, AkamaiGHost |
| Date | Tue, 06 Oct 2026 20:10:25 GMT, Tue, 06 Oct 2026 20:10:26 GMT, Tue, 06 Oct 2026 20:10:26 GMT |
| Content-Length | 0, 0 |
| Connection | close, close, close |
| Location | https://www.max.com/, https://www.hbomax.com/ |
| X-Cache | FunctionGeneratedResponse from cloudfront |
| Via | 1.1 1091fb2d690082d84a47c975bad5c850.cloudfront.net (CloudFront) |
| X-Amz-Cf-Pop | CDG50-P5 |
| X-Amz-Cf-Id | uaolGM9ygaDDo-7TZlKM1aNoA-2ubWW_02XYGPxI7DutuhpgvEAUsQ== |
| Strict-Transport-Security | max-age=31536000; includeSubDomains; preload, max-age=31536000 ; includeSubDomains ; preload, max-age=31536000 ; includeSubDomains ; preload |
| Cache-Control | max-age=0, public, max-age=120, s-maxage=270 |
| Expires | Tue, 06 Oct 2026 20:10:26 GMT, Tue, 06 Oct 2026 20:12:26 GMT |
| Set-Cookie | one=1; expires=Wed, 07-Oct-2026 08:10:26 GMT; path=/, countryCode=IN; expires=Wed, 07-Oct-2026 08:10:26 GMT; path=/; domain=.hbomax.com, city=KANPUR; expires=Wed, 07-Oct-2026 08:10:26 GMT; path=/, continent=AS; expires=Wed, 07-Oct-2026 08:10:26 GMT; path=/, one=1; expires=Wed, 07-Oct-2026 08:10:26 GMT; path=/, countryCode=IN; expires=Wed, 07-Oct-2026 08:10:26 GMT; path=/; domain=.hbomax.com, city=KANPUR; expires=Wed, 07-Oct-2026 08:10:26 GMT; path=/, continent=AS; expires=Wed, 07-Oct-2026 08:10:26 GMT; path=/ |
| Server-Timing | ak_p; desc="1791317426495_390070740_1885586795_10_11123_24_43_-";dur=1, ak_p; desc="1791317426728_390070756_1684689485_319_8745_25_27_-";dur=1 |
| Content-Type | text/html; charset=utf-8 |
| x-powered-by | engage-v2 |
| x-content-type-options | nosniff |
| Content-Security-Policy | script-src 'self' blob: data: https: 'unsafe-inline' 'unsafe-eval'; connect-src 'self' ws: https:; style-src 'self' 'unsafe-inline' https:; font-src 'self' https: data:; object-src 'none'; worker-src blob:; img-src 'self' blob: data: https:; frame-src 'self' blob: data: https:; base-uri 'self'; form-action 'self'; frame-ancestors 'none'; upgrade-insecure-requests; |
| ETag | "ijgg73gn8m1lncw" |
| MPULSE_CDN_CACHE | MISS |
| MPULSE_ORIGIN_TIME | 359 |