Technical Information
| HTTP Status Code | 202 |
| HTTP Version | HTTP/1.1 |
| HTTPS | ✔ Available |
| IP Address | 52.71.18.43 |
| Server Software | CloudFront |
| CDN | AWS CloudFront |
|
ℹ 🔵 Missing Content Security Policy | CSP is not configured. It helps prevent XSS attacks and content injection. |
|
ℹ 🔵 No Compression | The server does not use Gzip or Brotli. Enable compression to reduce bandwidth usage. |
HTTP Status Code 202
HTTP Version HTTP/1.1
HTTPS ✔ Available
IP Address 52.71.18.43
Server Software CloudFront
CDN AWS CloudFront
ℹ 🔵 Missing Content Security Policy CSP is not configured. It helps prevent XSS attacks and content injection.
ℹ 🔵 No Compression The server does not use Gzip or Brotli. Enable compression to reduce bandwidth usage.
Redirect Chain
| # | URL | HTTP Status Code | Status |
| 1 | https://nycgovparks.org:443 | 301 | HTTP/2 301 |
| 2 | https://www.nycgovparks.org/ | 202 | HTTP/2 202 |
#1 URL https://nycgovparks.org:443
HTTP Status Code 301
Status HTTP/2 301
#2 URL https://www.nycgovparks.org/
HTTP Status Code 202
Status HTTP/2 202
Performance
| DNS Lookup | 10.9 ms |
| TCP Connect | 12.2 ms |
| TLS Handshake | 5.7 ms |
| Time To First Byte (TTFB) | 22.9 ms |
| Content Download | 0 ms |
| Total Response Time | 23 ms |
DNS Lookup 10.9 ms
TCP Connect 12.2 ms
TLS Handshake 5.7 ms
Time To First Byte (TTFB) 22.9 ms
Content Download 0 ms
Total Response Time 23 ms
Security
| HTTPS | ✔ Enabled |
| HSTS | ✔ max-age=31536000; includeSubDomains; preload |
| CSP | ⚠ Not configured |
| X-Frame-Options | ✔ SAMEORIGIN |
| X-Content-Type-Options | ✔ nosniff |
| Referrer Policy | strict-origin-when-cross-origin |
| Permissions Policy | ✔ Configured |
| HTTP/2 | ⚠ HTTP/1.1 |
HTTPS ✔ Enabled
HSTS ✔ max-age=31536000; includeSubDomains; preload
CSP ⚠ Not configured
X-Frame-Options ✔ SAMEORIGIN
X-Content-Type-Options ✔ nosniff
Referrer Policy strict-origin-when-cross-origin
Permissions Policy ✔ Configured
HTTP/2 ⚠ HTTP/1.1
HTTP Headers
| Server
| CloudFront |
| Date
| Tue, 28 Jul 2026 00:17:54 GMT |
| Content-length
| 1999 |
| X-amzn-waf-action
| challenge |
| Cache-control
| no-store, max-age=0 |
| Content-type
| text/html; charset=UTF-8 |
| Access-control-allow-origin
| * |
| Access-control-max-age
| 86400 |
| Access-control-allow-methods
| OPTIONS,GET,POST |
| Access-control-expose-headers
| x-amzn-waf-action |
| X-cache
| Error from cloudfront |
| Via
| 1.1 b58ec9075455d7b944ead7f991bf40de.cloudfront.net (CloudFront) |
| X-amz-cf-pop
| CDG54-P2 |
| X-amz-cf-id
| iBJPEDfm26M2Y44x8i27si_0jc02VIe3yoxgu-Ttr2nsEcQ09PXt1w== |
| X-xss-protection
| 1; mode=block |
| X-frame-options
| SAMEORIGIN |
| Referrer-policy
| strict-origin-when-cross-origin |
| X-content-type-options
| nosniff |
| Strict-transport-security
| max-age=31536000; includeSubDomains; preload |
| Permissions-policy
| camera=(), microphone=(), geolocation=(), payment=(), usb=() |
Meta Tags
| Viewport | width=device-width, initial-scale=1 |
Server CloudFront
Date Tue, 28 Jul 2026 00:17:54 GMT
Content-length 1999
X-amzn-waf-action challenge
Cache-control no-store, max-age=0
Content-type text/html; charset=UTF-8
Access-control-allow-origin *
Access-control-max-age 86400
Access-control-allow-methods OPTIONS,GET,POST
Access-control-expose-headers x-amzn-waf-action
X-cache Error from cloudfront
Via 1.1 b58ec9075455d7b944ead7f991bf40de.cloudfront.net (CloudFront)
X-amz-cf-pop CDG54-P2
X-amz-cf-id iBJPEDfm26M2Y44x8i27si_0jc02VIe3yoxgu-Ttr2nsEcQ09PXt1w==
X-xss-protection 1; mode=block
X-frame-options SAMEORIGIN
Referrer-policy strict-origin-when-cross-origin
X-content-type-options nosniff
Strict-transport-security max-age=31536000; includeSubDomains; preload
Permissions-policy camera=(), microphone=(), geolocation=(), payment=(), usb=()