HTTP Response Headers Inspector

Check HTTP status codes (200, 301, 404), server technologies, compression, and security headers (CSP, HSTS).

📑

HTTP Response for max.com

HTTP/1.1 200 OK
Header Field Value
Status HTTP/1.1 200 OK
Server CloudFront, AkamaiGHost
Date Tue, 06 Oct 2026 20:10:25 GMT, Tue, 06 Oct 2026 20:10:26 GMT, Tue, 06 Oct 2026 20:10:26 GMT
Content-Length 0, 0
Connection close, close, close
Location https://www.max.com/, https://www.hbomax.com/
X-Cache FunctionGeneratedResponse from cloudfront
Via 1.1 1091fb2d690082d84a47c975bad5c850.cloudfront.net (CloudFront)
X-Amz-Cf-Pop CDG50-P5
X-Amz-Cf-Id uaolGM9ygaDDo-7TZlKM1aNoA-2ubWW_02XYGPxI7DutuhpgvEAUsQ==
Strict-Transport-Security max-age=31536000; includeSubDomains; preload, max-age=31536000 ; includeSubDomains ; preload, max-age=31536000 ; includeSubDomains ; preload
Cache-Control max-age=0, public, max-age=120, s-maxage=270
Expires Tue, 06 Oct 2026 20:10:26 GMT, Tue, 06 Oct 2026 20:12:26 GMT
Set-Cookie one=1; expires=Wed, 07-Oct-2026 08:10:26 GMT; path=/, countryCode=IN; expires=Wed, 07-Oct-2026 08:10:26 GMT; path=/; domain=.hbomax.com, city=KANPUR; expires=Wed, 07-Oct-2026 08:10:26 GMT; path=/, continent=AS; expires=Wed, 07-Oct-2026 08:10:26 GMT; path=/, one=1; expires=Wed, 07-Oct-2026 08:10:26 GMT; path=/, countryCode=IN; expires=Wed, 07-Oct-2026 08:10:26 GMT; path=/; domain=.hbomax.com, city=KANPUR; expires=Wed, 07-Oct-2026 08:10:26 GMT; path=/, continent=AS; expires=Wed, 07-Oct-2026 08:10:26 GMT; path=/
Server-Timing ak_p; desc="1791317426495_390070740_1885586795_10_11123_24_43_-";dur=1, ak_p; desc="1791317426728_390070756_1684689485_319_8745_25_27_-";dur=1
Content-Type text/html; charset=utf-8
x-powered-by engage-v2
x-content-type-options nosniff
Content-Security-Policy script-src 'self' blob: data: https: 'unsafe-inline' 'unsafe-eval'; connect-src 'self' ws: https:; style-src 'self' 'unsafe-inline' https:; font-src 'self' https: data:; object-src 'none'; worker-src blob:; img-src 'self' blob: data: https:; frame-src 'self' blob: data: https:; base-uri 'self'; form-action 'self'; frame-ancestors 'none'; upgrade-insecure-requests;
ETag "ijgg73gn8m1lncw"
MPULSE_CDN_CACHE MISS
MPULSE_ORIGIN_TIME 359