HTTP Response Headers Inspector

Check HTTP status codes (200, 301, 404), server technologies, compression, and security headers (CSP, HSTS).

📑

HTTP Response for stackoverflow.com

HTTP/1.1 403 Forbidden
Header Field Value
Status HTTP/1.1 403 Forbidden
Date Mon, 05 Oct 2026 12:19:39 GMT, Mon, 05 Oct 2026 12:19:39 GMT
Connection close, close
Location /questions
CF-Ray a45c603a8b8a59a2-DEL
CF-Cache-Status DYNAMIC
Cache-Control private
Server cloudflare, cloudflare
x-worker-origin-response-time 238000000
Strict-Transport-Security max-age=31536000; includeSubDomains
X-DNS-Prefetch-Control off, off
content-security-policy upgrade-insecure-requests; frame-ancestors 'self' https://stackexchange.com
feature-policy microphone 'none'; speaker 'none'
x-clacks-overhead GNU Terry Pratchett
x-frame-options SAMEORIGIN
x-request-guid 44a071a7-0b75-43c6-9350-b06d28a7fe27
Set-Cookie prov=5479b752-e164-44a9-9509-0e50f01245e2; expires=Tue, 05 Oct 2027 12:19:39 GMT; domain=.stackoverflow.com; path=/; secure; samesite=none; httponly, __cflb=02DiuFA7zZL3enAQJD3AX8ZzvyzLcaG7vorKETworfYBe; HttpOnly; SameSite=None; Secure; Path=/; Expires=Tue, 06 Oct 2026 11:19:39 GMT, prov=5479b752-e164-44a9-9509-0e50f01245e2; Path=/; HttpOnly; Domain=stackoverflow.com
set-cookie __cf_bm=BnMcI4ijtYf6dVpGtTAV9P7y.A_jmMlqy1vXwOP59sQ-1791202779.288932-1.0.1.1-Q2KrR_JDmFcwKpBCocLEA4WPTtahO4WZU8ibBSJvvkgvnPLktrEDOAbWrAT_pqveGoJ9SfDCavC.KvCXBaU6FuMKFtDFaqEBULmD15Gt7XRwPA02VJ.18P_p8DBAKwlUgoGd8kq66UgqUR0LolZhh1dK7mNtt_4oE0omh0mkmsA; HttpOnly; SameSite=None; Secure; Path=/; Domain=stackoverflow.com; Expires=Mon, 05 Oct 2026 12:49:39 GMT, __cf_bm=yMKiSQFaHMxw3cHCuYZSS9LqJNYgZWQaSKepbEyW7xE-1791202779.7434459-1.0.1.1-Tz7khXwnJwwYV.leKXQJfHy7VTzXNV9cirpvj8SOV_9mQnYWNV2_gKsti8.ONIoq3CY.Tv8wSSa14PvdbqfEOF7xKMoPnV15lQlz2gcXc7xBSU_CF8_B4SpYIGvL239XxnbJdZnz_qoJHNDEXrjkb13jWZSmY9LASvs4xN5i_kU; HttpOnly; SameSite=None; Secure; Path=/; Domain=stackoverflow.com; Expires=Mon, 05 Oct 2026 12:49:39 GMT
Content-Type text/html; charset=UTF-8
Content-Length 5273
Accept-Ch Sec-CH-UA-Bitness, Sec-CH-UA-Arch, Sec-CH-UA-Full-Version, Sec-CH-UA-Mobile, Sec-CH-UA-Model, Sec-CH-UA-Platform-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Platform, Sec-CH-UA, UA-Bitness, UA-Arch, UA-Full-Version, UA-Mobile, UA-Model, UA-Platform-Version, UA-Platform, UA
Cf-Mitigated challenge
Content-Security-Policy default-src 'none'; script-src 'nonce-4tyA96am01Nkw53taB1Oh7' 'unsafe-eval' https://challenges.cloudflare.com; script-src-attr 'none'; style-src 'unsafe-inline'; img-src 'self' https://challenges.cloudflare.com; connect-src 'self' https://challenges.cloudflare.com; frame-src 'self' https://challenges.cloudflare.com blob:; child-src 'self' https://challenges.cloudflare.com blob:; worker-src blob:; form-action http: https:; base-uri 'self'
Critical-Ch Sec-CH-UA-Bitness, Sec-CH-UA-Arch, Sec-CH-UA-Full-Version, Sec-CH-UA-Mobile, Sec-CH-UA-Model, Sec-CH-UA-Platform-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Platform, Sec-CH-UA, UA-Bitness, UA-Arch, UA-Full-Version, UA-Mobile, UA-Model, UA-Platform-Version, UA-Platform, UA
Cross-Origin-Embedder-Policy require-corp
Cross-Origin-Opener-Policy same-origin
Cross-Origin-Resource-Policy same-origin
Origin-Agent-Cluster ?1
Permissions-Policy accelerometer=(),camera=(),clipboard-read=(),clipboard-write=(),geolocation=(),gyroscope=(),hid=(),magnetometer=(),microphone=(),payment=(),publickey-credentials-get=(),screen-wake-lock=(),serial=(),sync-xhr=(),usb=(),xr-spatial-tracking=*
Referrer-Policy same-origin
Server-Timing chlray;desc="a45c603d6c2b7ec6"
X-Content-Type-Options nosniff
X-Frame-Options SAMEORIGIN
CF-RAY a45c603d6c2b7ec6-DEL