HTTP Security Headers
attachmail.ru
Final status: 200 · Server: nginx
http://attachmail.ru (302)https://mail.ru/ (302)https://login.vk.ru/?act=autologin&app_id=7539952&redirect_uri=https%3A%2F%2Faccount.mail.ru%2Flogin%3Fautologin_exp%3Dv22%26autologin_project%3Dhome%26page%3Dhttps%253A%252F%252Fmail.ru%252F%253Fautologin%253D1782230122&state=6f6ab4e1ae1d4b53a2391f03ce7a584a&uuid=8d1f7fae-3ded-4ccb-979f-744d74d09425&service_group=oid_78q9MkXkKqLGmDopMH4Ub (302)https://account.mail.ru/login?autologin_exp=v22&autologin_project=home&errorCode=11300&errorText=invalid+user&page=https%3A%2F%2Fmail.ru%2F%3Fautologin%3D1782230122&state=6f6ab4e1ae1d4b53a2391f03ce7a584a (200)
Security Headers
Strict-Transport-Security (HSTS)
Forces browsers to use HTTPS, preventing protocol-downgrade attacks.
Content-Security-Policy (CSP)
Limits where scripts/resources can load from — the strongest defense against XSS.
X-Frame-Options — missing
Blocks the site from being embedded in iframes (clickjacking protection).
X-Content-Type-Options
Stops browsers from MIME-sniffing responses away from the declared type.
Referrer-Policy — missing
Controls how much referrer information is sent to other sites.
Permissions-Policy — missing
Restricts access to browser features like camera, microphone, geolocation.