HTTP Security Headers
state.mn.us
Final status: 200 · Server: Apache
http://state.mn.us (302)https://state.mn.us/ (302)https://mn.gov/ (302)http://validate.perfdrive.com/d5bd5333eafe8b0ccd6023ba818d1aa6/?ssa=f5903efc-a9e6-4829-85b2-dad91dafea4a&ssb=38984244392&ssc=https%3A%2F%2Fmn.gov%2F&ssi=07c3ad14-bf56-4ca0-967b-55f50854bf90&ssk=support@shieldsquare.com&ssm=04888958802098245109030996167517&ssn=f6f5c1d0a5550e1333a1fa19ebcfe969e0c5be30da2d-7b31-46d8-983dda&sso=460d35db-f92c00971c125d84f932f08eb50fd291f11cd4a694bc347d&ssp=90135085211786696731178668730150555&ssq=53701358412248583768684122581000758897601&ssr=NTQuMTk3LjMyLjIyMw==&sst=Mozilla/5.0%20(compatible;%20DNS.pizza/1.0;%20+https://dns.pizza)&ssu=&ssv=&ssw=&ssx=W10= (200)
Security Headers
Strict-Transport-Security (HSTS) — missing
Forces browsers to use HTTPS, preventing protocol-downgrade attacks.
Content-Security-Policy (CSP) — missing
Limits where scripts/resources can load from — the strongest defense against XSS.
X-Frame-Options — missing
Blocks the site from being embedded in iframes (clickjacking protection).
X-Content-Type-Options — missing
Stops browsers from MIME-sniffing responses away from the declared type.
Referrer-Policy — missing
Controls how much referrer information is sent to other sites.
Permissions-Policy — missing
Restricts access to browser features like camera, microphone, geolocation.