Technical Information
| HTTP Status Code | 200 |
| HTTP Version | HTTP/1.1 |
| HTTPS | ✔ Available |
| IP Address | 150.171.110.117 |
| Compression | gzip |
|
🔒 🟡 Mixed Content (2 HTTP resources) | The page is served over HTTPS but loads 2 resource(s) over HTTP. This may be blocked in modern browsers. |
|
ℹ 🔵 Missing Content Security Policy | CSP is not configured. It helps prevent XSS attacks and content injection. |
HTTP Status Code 200
HTTP Version HTTP/1.1
HTTPS ✔ Available
IP Address 150.171.110.117
Compression gzip
🔒 🟡 Mixed Content (2 HTTP resources) The page is served over HTTPS but loads 2 resource(s) over HTTP. This may be blocked in modern browsers.
ℹ 🔵 Missing Content Security Policy CSP is not configured. It helps prevent XSS attacks and content injection.
Performance
| DNS Lookup | 152.4 ms |
| TCP Connect | 153.9 ms |
| TLS Handshake | 6.2 ms |
| Time To First Byte (TTFB) | 219.3 ms |
| Content Download | 0.2 ms |
| Total Response Time | 219.4 ms |
DNS Lookup 152.4 ms
TCP Connect 153.9 ms
TLS Handshake 6.2 ms
Time To First Byte (TTFB) 219.3 ms
Content Download 0.2 ms
Total Response Time 219.4 ms
Security
| HTTPS | ✔ Enabled |
| HSTS | ✔ max-age=31536000; includeSubdomains; preload |
| CSP | ⚠ Not configured |
| X-Frame-Options | ✔ SAMEORIGIN |
| X-Content-Type-Options | ✔ nosniff |
| Referrer Policy | strict-origin-when-cross-origin |
| HTTP/2 | ⚠ HTTP/1.1 |
HTTPS ✔ Enabled
HSTS ✔ max-age=31536000; includeSubdomains; preload
CSP ⚠ Not configured
X-Frame-Options ✔ SAMEORIGIN
X-Content-Type-Options ✔ nosniff
Referrer Policy strict-origin-when-cross-origin
HTTP/2 ⚠ HTTP/1.1
SEO Quick Check
| Title | Results and submissions : REF 2021 |
Title Results and submissions : REF 2021
Detected Technologies
| Technology | Bootstrap jQuery Google Analytics |
Technology Bootstrap jQuery Google Analytics
HTTP Headers
| Date
| Tue, 28 Jul 2026 04:11:12 GMT |
| Content-type
| text/html; charset=utf-8 |
| Content-encoding
| gzip |
| Set-cookie
| ARRAffinitySameSite=b38557ed155804dc1c4cfb9b76411b0366cffab27791977a73712943928b2ff7;Path=/;HttpOnly;SameSite=None;Secure;Domain=ref2021-resultsapp-live.azurewebsites.net |
| Vary
| Origin,Accept-Encoding |
| Strict-transport-security
| max-age=31536000; includeSubdomains; preload |
| Request-context
| appId=cid-v1:b992e0b9-e96b-4d4d-a9c2-15607311bafc |
| X-frame-options
| SAMEORIGIN |
| X-xss-protection
| 1; mode=block |
| X-content-type-options
| nosniff |
| Referrer-policy
| strict-origin-when-cross-origin |
| Content-security-policy-report-only
| default-src 'self'; style-src 'unsafe-inline' 'self' fonts.googleapis.com; font-src fonts.googleapis.com fonts.gstatic.com ka-f.fontawesome.com; img-src 'self' 2021.ref.ac.uk ref.ac.uk data:; script-src 'self' 'unsafe-inline' kit.fontawesome.com; connect-src ka-f.fontawesome.com; |
| X-azure-ref
| 20260728T041112Z-er19f7f4947z8p2xhC1PARhg3w0000000hq00000000016dn |
| X-cache
| CONFIG_NOCACHE |
Meta Tags
| Viewport | width=device-width, initial-scale=1 |
Date Tue, 28 Jul 2026 04:11:12 GMT
Content-type text/html; charset=utf-8
Content-encoding gzip
Set-cookie ARRAffinitySameSite=b38557ed155804dc1c4cfb9b76411b0366cffab27791977a73712943928b2ff7;Path=/;HttpOnly;SameSite=None;Secure;Domain=ref2021-resultsapp-live.azurewebsites.net
Vary Origin,Accept-Encoding
Strict-transport-security max-age=31536000; includeSubdomains; preload
Request-context appId=cid-v1:b992e0b9-e96b-4d4d-a9c2-15607311bafc
X-frame-options SAMEORIGIN
X-xss-protection 1; mode=block
X-content-type-options nosniff
Referrer-policy strict-origin-when-cross-origin
Content-security-policy-report-only default-src 'self'; style-src 'unsafe-inline' 'self' fonts.googleapis.com; font-src fonts.googleapis.com fonts.gstatic.com ka-f.fontawesome.com; img-src 'self' 2021.ref.ac.uk ref.ac.uk data:; script-src 'self' 'unsafe-inline' kit.fontawesome.com; connect-src ka-f.fontawesome.com;
X-azure-ref 20260728T041112Z-er19f7f4947z8p2xhC1PARhg3w0000000hq00000000016dn
X-cache CONFIG_NOCACHE