HTTP Security Headers
email.imperial.ac.uk
Final status: 200
http://email.imperial.ac.uk (307)https://login.microsoftonline.com/common/oauth2/authorize?client_id=00000002-0000-0ff1-ce00-000000000000&redirect_uri=https%3a%2f%2foutlook.office.com%2fowa%2f&resource=00000002-0000-0ff1-ce00-000000000000&response_mode=form_post&response_type=code+id_token&scope=openid&msafed=1&msaredir=1&client-request-id=a51a4034-94a4-7d0c-cf3f-887822147d4c&protectedtoken=true&claims=%7b%22id_token%22%3a%7b%22xms_cc%22%3a%7b%22values%22%3a%5b%22CP1%22%5d%7d%7d%7d&domain_hint=ic.ac.uk&nonce=638646663671728236.bf5ce615-8d3e-4f26-becd-aad5f0b6281e&state=Dcs7EoAgDEXRoLVL4ZfIg-1AgBnHwspx-1Kc211DRPuyLSasUIYUnAAEOWYuLHBtJh2IyZYuw56TYdvQbmvtaYYGLnGY9R7--aq_1FV17_0D (200)
Security Headers
Strict-Transport-Security (HSTS)
Forces browsers to use HTTPS, preventing protocol-downgrade attacks.
Content-Security-Policy (CSP) — missing
Limits where scripts/resources can load from — the strongest defense against XSS.
X-Frame-Options DENY
Blocks the site from being embedded in iframes (clickjacking protection).
X-Content-Type-Options
Stops browsers from MIME-sniffing responses away from the declared type.
Referrer-Policy — missing
Controls how much referrer information is sent to other sites.
Permissions-Policy — missing
Restricts access to browser features like camera, microphone, geolocation.