Technical Information
| HTTP Status Code | 200 |
| HTTP Version | HTTP/1.1 |
| HTTPS | ✔ Available |
| IP Address | 202.134.12.124 |
| Compression | gzip |
|
🕐 🟡 Slow Response (1453 ms) | Response time exceeds 1 second. Consider optimizing the server or using caching. |
|
ℹ 🔵 Missing X-Frame-Options | The site can be embedded in iframes by third parties (clickjacking risk). |
HTTP Status Code 200
HTTP Version HTTP/1.1
HTTPS ✔ Available
IP Address 202.134.12.124
Compression gzip
🕐 🟡 Slow Response (1453 ms) Response time exceeds 1 second. Consider optimizing the server or using caching.
ℹ 🔵 Missing X-Frame-Options The site can be embedded in iframes by third parties (clickjacking risk).
Redirect Chain
| # | URL | HTTP Status Code | Status |
| 1 | https://robi.com.bd:443 | 301 | HTTP/1.1 301 Moved Permanently |
| 2 | https://www.robi.com.bd/ | 307 | HTTP/1.1 307 Temporary Redirect |
| 3 | https://www.robi.com.bd/en | 200 | HTTP/1.1 200 OK |
#1 URL https://robi.com.bd:443
HTTP Status Code 301
Status HTTP/1.1 301 Moved Permanently
#2 URL https://www.robi.com.bd/
HTTP Status Code 307
Status HTTP/1.1 307 Temporary Redirect
#3 URL https://www.robi.com.bd/en
HTTP Status Code 200
Status HTTP/1.1 200 OK
Performance
| DNS Lookup | 5.2 ms |
| TCP Connect | 205.6 ms |
| TLS Handshake | 404.5 ms |
| Time To First Byte (TTFB) | 853.2 ms |
| Content Download | 599.7 ms |
| Total Response Time | 1452.9 ms |
DNS Lookup 5.2 ms
TCP Connect 205.6 ms
TLS Handshake 404.5 ms
Time To First Byte (TTFB) 853.2 ms
Content Download 599.7 ms
Total Response Time 1452.9 ms
Security
| HTTPS | ✔ Enabled |
| HSTS | ✔ max-age=31536000; includeSubDomains |
| CSP | ✔ Configured |
| X-Frame-Options | ⚠ Not configured |
| X-Content-Type-Options | ✔ nosniff |
| Referrer Policy | same-origin |
| Permissions Policy | ✔ Configured |
| HTTP/2 | ⚠ HTTP/1.1 |
HTTPS ✔ Enabled
HSTS ✔ max-age=31536000; includeSubDomains
CSP ✔ Configured
X-Frame-Options ⚠ Not configured
X-Content-Type-Options ✔ nosniff
Referrer Policy same-origin
Permissions Policy ✔ Configured
HTTP/2 ⚠ HTTP/1.1
SEO Quick Check
| Title | My Robi |
| Meta Description | My Robi App |
Title My Robi
Meta Description My Robi App
Detected Technologies
| Technology | React Google Analytics Google Tag Manager Node.js Next.js |
Technology React Google Analytics Google Tag Manager Node.js Next.js
HTTP Headers
| Cache-Control
| private, no-cache, no-store, max-age=0, must-revalidate |
| Content-Encoding
| gzip |
| Content-Security-Policy
| default-src 'self'; script-src 'self' 'unsafe-inline' https://*.bka.sh https://*.google.com https://www.youtube.com https://cdn.userway.org https://www.googletagmanager.com https://analytics.tiktok.com https://connect.facebook.net https://livechat.myalice.ai; style-src 'self' 'unsafe-inline' https://*.bka.sh https://cdn.userway.org https://fonts.googleapis.com; img-src 'self' data: blob: https://*.bka.sh https://www.facebook.com https://s3-ap-southeast-1.amazonaws.com https://webapi.robi.com.bd https://webapi-preprod.robi.com.bd https://storage.googleapis.com https://cdn.userway.org https://connect.facebook.net https://www.google.com.bd https://myrobi-prod-static.robi.com.bd; connect-src 'self' https://*.bka.sh https://*.googleapis.com https://securetoken.googleapis.com https://payment.bkash.com https://sg-channels.mevrik.com https://webapi.robi.com.bd https://map.barikoi.com https://tiles.bmapsbd.com https://planet.tiles.bmapsbd.com https://api.userway.org https://robi-api.myalice.ai wss://ws-ap1.pusher.com https://sockjs-ap1.pusher.com https://www.google.com https://analytics.google.com https://stats.g.doubleclick.net https://analytics.tiktok.com; font-src 'self' https://fonts.gstatic.com https://cdn.userway.org; frame-src https://*.firebaseapp.com https://*.bka.sh https://*.google.com https://ced.robi.com.bd https://robi-video-chat.mevrik.net https://www.facebook.com https://www.youtube.com https://wms-web.robi.com.bd https://wms.robi.com.bd https://cdn.userway.org https://www.googletagmanager.com https://connect.facebook.net; worker-src 'self' blob:; form-action 'self' https://www.facebook.com; object-src 'none'; base-uri 'self'; frame-ancestors 'none'; upgrade-insecure-requests; |
| Content-Type
| text/html; charset=utf-8 |
| Cross-Origin-Embedder-Policy
| unsafe-none |
| Cross-Origin-Opener-Policy
| unsafe-none |
| Cross-Origin-Resource-Policy
| cross-origin |
| Date
| Thu, 23 Jul 2026 10:34:30 GMT |
| Link
| ; rel=preload; as="font"; crossorigin=""; type="font/woff2", ; rel=preload; as="font"; crossorigin=""; type="font/woff2", ; rel=preload; as="font"; crossorigin=""; type="font/woff2", ; rel=preload; as="font"; crossorigin=""; type="font/woff2", ; rel=preload; as="font"; crossorigin=""; type="font/woff2", ; rel=preload; as="font"; crossorigin=""; type="font/woff2", ; rel=preload; as="font"; crossorigin=""; type="font/woff2", ; rel=preload; as="font"; crossorigin=""; type="font/woff2", ; rel=preload; as="font"; crossorigin=""; type="font/woff2", ; rel=preload; as="font"; crossorigin=""; type="font/woff2", ; rel=preload; as="style", ; rel=preload; as="style", ; rel=preload; as="style", ; rel=preload; as="style", ; rel=preload; as="style", ; rel=preload; as="style", ; rel=preload; as="style" |
| Permissions-Policy
| camera=*, microphone=*, geolocation=*, fullscreen=() |
| Referrer-Policy
| same-origin |
| Strict-Transport-Security
| max-age=31536000; includeSubDomains |
| Vary
| rsc, next-router-state-tree, next-router-prefetch, next-router-segment-prefetch, Accept-Encoding |
| X-Content-Type-Options
| nosniff |
| X-Middleware-Rewrite
| /en |
| X-Pathname
| /en |
| Transfer-Encoding
| chunked |
Meta Tags
| Viewport | width=device-width, initial-scale=1 |
| Description | My Robi App |
| Mobile-web-app-capable | yes |
| Apple-mobile-web-app-title | My Robi |
| Apple-mobile-web-app-status-bar-style | default |
Cache-Control private, no-cache, no-store, max-age=0, must-revalidate
Content-Encoding gzip
Content-Security-Policy default-src 'self'; script-src 'self' 'unsafe-inline' https://*.bka.sh https://*.google.com https://www.youtube.com https://cdn.userway.org https://www.googletagmanager.com https://analytics.tiktok.com https://connect.facebook.net https://livechat.myalice.ai; style-src 'self' 'unsafe-inline' https://*.bka.sh https://cdn.userway.org https://fonts.googleapis.com; img-src 'self' data: blob: https://*.bka.sh https://www.facebook.com https://s3-ap-southeast-1.amazonaws.com https://webapi.robi.com.bd https://webapi-preprod.robi.com.bd https://storage.googleapis.com https://cdn.userway.org https://connect.facebook.net https://www.google.com.bd https://myrobi-prod-static.robi.com.bd; connect-src 'self' https://*.bka.sh https://*.googleapis.com https://securetoken.googleapis.com https://payment.bkash.com https://sg-channels.mevrik.com https://webapi.robi.com.bd https://map.barikoi.com https://tiles.bmapsbd.com https://planet.tiles.bmapsbd.com https://api.userway.org https://robi-api.myalice.ai wss://ws-ap1.pusher.com https://sockjs-ap1.pusher.com https://www.google.com https://analytics.google.com https://stats.g.doubleclick.net https://analytics.tiktok.com; font-src 'self' https://fonts.gstatic.com https://cdn.userway.org; frame-src https://*.firebaseapp.com https://*.bka.sh https://*.google.com https://ced.robi.com.bd https://robi-video-chat.mevrik.net https://www.facebook.com https://www.youtube.com https://wms-web.robi.com.bd https://wms.robi.com.bd https://cdn.userway.org https://www.googletagmanager.com https://connect.facebook.net; worker-src 'self' blob:; form-action 'self' https://www.facebook.com; object-src 'none'; base-uri 'self'; frame-ancestors 'none'; upgrade-insecure-requests;
Content-Type text/html; charset=utf-8
Cross-Origin-Embedder-Policy unsafe-none
Cross-Origin-Opener-Policy unsafe-none
Cross-Origin-Resource-Policy cross-origin
Date Thu, 23 Jul 2026 10:34:30 GMT
Link ; rel=preload; as="font"; crossorigin=""; type="font/woff2", ; rel=preload; as="font"; crossorigin=""; type="font/woff2", ; rel=preload; as="font"; crossorigin=""; type="font/woff2", ; rel=preload; as="font"; crossorigin=""; type="font/woff2", ; rel=preload; as="font"; crossorigin=""; type="font/woff2", ; rel=preload; as="font"; crossorigin=""; type="font/woff2", ; rel=preload; as="font"; crossorigin=""; type="font/woff2", ; rel=preload; as="font"; crossorigin=""; type="font/woff2", ; rel=preload; as="font"; crossorigin=""; type="font/woff2", ; rel=preload; as="font"; crossorigin=""; type="font/woff2", ; rel=preload; as="style", ; rel=preload; as="style", ; rel=preload; as="style", ; rel=preload; as="style", ; rel=preload; as="style", ; rel=preload; as="style", ; rel=preload; as="style"
Permissions-Policy camera=*, microphone=*, geolocation=*, fullscreen=()
Referrer-Policy same-origin
Strict-Transport-Security max-age=31536000; includeSubDomains
Vary rsc, next-router-state-tree, next-router-prefetch, next-router-segment-prefetch, Accept-Encoding
X-Content-Type-Options nosniff
X-Middleware-Rewrite /en
X-Pathname /en
Transfer-Encoding chunked