HTTP Response Headers Inspector

Check HTTP status codes (200, 301, 404), server technologies, compression, and security headers (CSP, HSTS).

📑

HTTP Response for spotify.com

HTTP/1.1 200 OK
Header Field Value
Status HTTP/1.1 200 OK
location https://www.spotify.com/, https://open.spotify.com/
strict-transport-security max-age=31536000, max-age=31536000, max-age=31536000
x-content-type-options nosniff, nosniff, nosniff
alt-svc h3=":443"; ma=2592000,h3-29=":443"; ma=2592000, h3=":443";ma=86400,h3-29=":443";ma=86400,h3-27=":443";ma=86400
vary Accept-Encoding
date Tue, 06 Oct 2026 19:19:14 GMT
server envoy, envoy, envoy
via HTTP/2 edgeproxy, 1.1 google, HTTP/2 edgeproxy, 1.1 google, 1.1 varnish, HTTP/1.1 fringe, HTTP/2 edgeproxy, 1.1 google, 1.1 varnish
Transfer-Encoding chunked
Alt-Svc h3=":443"; ma=2592000
Connection close, close, close
Accept-Ranges bytes, bytes
Date Tue, 06 Oct 2026 19:19:14 GMT, Tue, 06 Oct 2026 19:19:15 GMT
X-Served-By cache-del-vibw2260028-DEL, cache-del-vibw2260027-DEL
X-Cache MISS, MISS
X-Cache-Hits 0, 0
X-Timer S1791314355.840429,VS0,VE114, S1791314355.128403,VS0,VE138
Vary Accept-Encoding, Accept-Encoding
set-cookie sp_t=ed6a2e0f-375b-4057-9d98-13111458c12e; path=/; expires=Wed, 06 Oct 2027 19:19:15 GMT; domain=.spotify.com; samesite=none; secure, sp_landing=https%3A%2F%2Fopen.spotify.com%2F%3Fsp_cid%3Ded6a2e0f-375b-4057-9d98-13111458c12e%26device%3Ddesktop; path=/; expires=Wed, 07 Oct 2026 19:19:15 GMT; domain=.spotify.com; samesite=none; secure; httponly, sp_t=ed6a2e0f-375b-4057-9d98-13111458c12e; Max-Age=31536000; Path=/; Domain=.spotify.com; Secure, sp_new=1; Max-Age=86400; Path=/; Domain=.spotify.com; Secure, sp_landing=https%3A%2F%2Fopen.spotify.com%2F; Max-Age=86400; Path=/; Domain=.spotify.com; HttpOnly; Secure
content-security-policy script-src 'self' 'unsafe-eval' blob: open.spotifycdn.com open-review.spotifycdn.com quicksilver.scdn.co www.google-analytics.com www.googletagmanager.com static.ads-twitter.com analytics.twitter.com s.pinimg.com sc-static.net https://www.google.com/recaptcha/ cdn.ravenjs.com connect.facebook.net www.gstatic.com sb.scorecardresearch.com pixel-static.spotify.com cdn.cookielaw.org geolocation.onetrust.com www.fastly-insights.com static.hotjar.com script.hotjar.com https://www.googleadservices.com/pagead/conversion_async.js https://www.googleadservices.com/pagead/conversion/ https://analytics.tiktok.com/i18n/pixel/sdk.js https://analytics.tiktok.com/i18n/pixel/identify.js https://analytics.tiktok.com/i18n/pixel/config.js https://www.redditstatic.com/ads/pixel.js https://t.contentsquare.net/uxa/22f14577e19f3.js https://get.microsoft.com/badge/ms-store-badge.bundled.js https://cdn.us.heap-api.com https://heapanalytics.com 'sha256-WfsTi7oVogdF9vq5d14s2birjvCglqWF842fyHhzoNw=' 'sha256-KRzjHxCdT8icNaDOqPBdY0AlKiIh5F8r4bnbe1PQwss=' 'sha256-Z5wh7XXSBR1+mTxLSPFhywCZJt77+uP1GikAgPIsu2s=' 'sha256-o2wzIImHJ4+WWE5DCTR+myWU0UNml0+wwpDXRo++vII='; frame-ancestors 'self' https://adgen-dev.spotify.com/account/*/ad/*/details https://adgen-dev.spotify.com/preview/* https://local.spotify.net/account/*/ad/*/details https://local.spotify.net/preview/* https://app.smartly.io/*;
content-type text/html; charset=utf-8
x-spotify-open-index true
x-envoy-upstream-service-time 14