Technical Information
| HTTP Status Code | 403 |
| HTTP Version | HTTP/1.1 |
| HTTPS | ✔ Available |
| IP Address | 104.18.34.54 |
| Server Software | cloudflare |
| CDN | Cloudflare |
| Compression | gzip |
|
🚫 🟡 HTTP 403 Error | The server returned a 403 error. Check the access configuration. |
HTTP Status Code 403
HTTP Version HTTP/1.1
HTTPS ✔ Available
IP Address 104.18.34.54
Server Software cloudflare
CDN Cloudflare
Compression gzip
🚫 🟡 HTTP 403 Error The server returned a 403 error. Check the access configuration.
Redirect Chain
| # | URL | HTTP Status Code | Status |
| 1 | https://searspartsdirect.com:443 | 301 | HTTP/2 301 |
| 2 | https://www.searspartsdirect.com/ | 403 | HTTP/2 403 |
#1 URL https://searspartsdirect.com:443
HTTP Status Code 301
Status HTTP/2 301
#2 URL https://www.searspartsdirect.com/
HTTP Status Code 403
Status HTTP/2 403
Performance
| DNS Lookup | 22.1 ms |
| TCP Connect | 24.1 ms |
| TLS Handshake | 9.4 ms |
| Time To First Byte (TTFB) | 40.4 ms |
| Content Download | 0.3 ms |
| Total Response Time | 40.7 ms |
DNS Lookup 22.1 ms
TCP Connect 24.1 ms
TLS Handshake 9.4 ms
Time To First Byte (TTFB) 40.4 ms
Content Download 0.3 ms
Total Response Time 40.7 ms
Security
| HTTPS | ✔ Enabled |
| HSTS | ✔ max-age=63072000; includeSubdomains; preload |
| CSP | ✔ Configured |
| X-Frame-Options | ✔ SAMEORIGIN |
| X-Content-Type-Options | ✔ nosniff |
| Referrer Policy | same-origin |
| Permissions Policy | ✔ Configured |
| HTTP/2 | ⚠ HTTP/1.1 |
HTTPS ✔ Enabled
HSTS ✔ max-age=63072000; includeSubdomains; preload
CSP ✔ Configured
X-Frame-Options ✔ SAMEORIGIN
X-Content-Type-Options ✔ nosniff
Referrer Policy same-origin
Permissions Policy ✔ Configured
HTTP/2 ⚠ HTTP/1.1
SEO Quick Check
| Title | Just a moment... |
| Robots Meta | noindex,nofollow |
Title Just a moment...
Robots Meta noindex,nofollow
Detected Technologies
| Technology | Google Analytics Google Tag Manager Cloudflare Stripe |
Technology Google Analytics Google Tag Manager Cloudflare Stripe
HTTP Headers
| Date | Wed, 22 Jul 2026 23:49:01 GMT |
| Content-type | text/html; charset=UTF-8 |
| Accept-ch | Sec-CH-UA-Bitness, Sec-CH-UA-Arch, Sec-CH-UA-Full-Version, Sec-CH-UA-Mobile, Sec-CH-UA-Model, Sec-CH-UA-Platform-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Platform, Sec-CH-UA, UA-Bitness, UA-Arch, UA-Full-Version, UA-Mobile, UA-Model, UA-Platform-Version, UA-Platform, UA |
| Cf-mitigated | challenge |
| Content-security-policy | default-src 'none'; script-src 'nonce-hev3JgjUfIZxotkUDbeocS' 'unsafe-eval' https://challenges.cloudflare.com; script-src-attr 'none'; style-src 'unsafe-inline'; img-src 'self' https://challenges.cloudflare.com; connect-src 'self' https://challenges.cloudflare.com; frame-src 'self' https://challenges.cloudflare.com blob:; child-src 'self' https://challenges.cloudflare.com blob:; worker-src blob:; form-action http: https:; base-uri 'self' |
| Server | cloudflare |
| Critical-ch | Sec-CH-UA-Bitness, Sec-CH-UA-Arch, Sec-CH-UA-Full-Version, Sec-CH-UA-Mobile, Sec-CH-UA-Model, Sec-CH-UA-Platform-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Platform, Sec-CH-UA, UA-Bitness, UA-Arch, UA-Full-Version, UA-Mobile, UA-Model, UA-Platform-Version, UA-Platform, UA |
| Cross-origin-embedder-policy | require-corp |
| Cross-origin-opener-policy | same-origin |
| Cross-origin-resource-policy | same-origin |
| Origin-agent-cluster | ?1 |
| Permissions-policy | accelerometer=(),camera=(),clipboard-read=(),clipboard-write=(),geolocation=(),gyroscope=(),hid=(),magnetometer=(),microphone=(),payment=(),publickey-credentials-get=(),screen-wake-lock=(),serial=(),sync-xhr=(),usb=(),xr-spatial-tracking=* |
| Referrer-policy | same-origin |
| Server-timing | chlray;desc="a1f656e97e507a75" |
| X-content-type-options | nosniff |
| X-frame-options | SAMEORIGIN |
| Vary | accept-encoding |
| Set-cookie | __cf_bm=MXUmdbXZdxY9eu_3iQ7vgexCudh6L6A84q2TnH8Ozd4-1784764141.0403054-1.0.1.1-.LsOA8ouCvra8_x4NKlWYLXUqzV9ZPeBs1V6Jq9Oe_dvpsbu48mhERdJMrRsGVYMe47tpx8iUAIWlxjol8nrbmxf6gZc170mUHJOwYVQtC77_DgxOFmC5QM6tvRLjs0Q; HttpOnly; SameSite=None; Secure; Path=/; Domain=www.searspartsdirect.com; Expires=Thu, 23 Jul 2026 00:19:01 GMT |
| Expect-ct | max-age=86400, enforce |
| X-xss-protection | 1; mode=block |
| Content-security-policy-report-only | default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' cdn.jsdelivr.net js.stripe.com *.criteo.com *.simonsignal.com www.facebook.com connect.facebook.net bat.bing.com *.clarity.ms *.vibe.co www.google-analytics.com cdn.cookielaw.org *.optimizely.com cdnjs.cloudflare.com cdn.debugbear.com googleads.g.doubleclick.net d229tanlyij0i7.cloudfront.net d3cv1fywnihry0.cloudfront.net a61aa9fd029d.cdn4.forter.com js-agent.newrelic.com ui.powerreviews.com payment.searshomeservices.com tags.fullcontact.com www.googletagmanager.com www.paypal.com cdn.id5-sync.com mpsnare.iesnare.com d-code.liadm.com 8quntm5h1h.execute-api.us-east-1.amazonaws.com; frame-src 'self' js.stripe.com payment.searshomeservices.com offers.searshomeservices.com www.googletagmanager.com i.liadm.com gum.criteo.com gumi.criteo.com www.paypal.com c.searspartsdirect.com www.facebook.com connect.facebook.net a25563730275.cdn.optimizely.com; connect-src * data: blob: 'unsafe-inline'; img-src * data: blob: 'unsafe-inline'; media-src * data: blob: 'unsafe-inline'; style-src * data: blob: 'unsafe-inline'; font-src * data: blob: 'unsafe-inline'; worker-src * data: blob: 'unsafe-inline'; base-uri 'self'; form-action 'self' www.facebook.com; frame-ancestors 'self'; report-to report-endpoint; |
| Reporting-endpoints | report-endpoint="https://api.searspartsdirect.com/report-uri" |
| Strict-transport-security | max-age=63072000; includeSubdomains; preload |
| X-bot-score | 1 |
| X-verified-bot | false |
| Content-encoding | gzip |
| Cf-ray | a1f656e97e507a75-CDG |
| Alt-svc | h3=":443"; ma=86400 |
Meta Tags
| Content-Type | text/html; charset=UTF-8 |
| X-UA-Compatible | IE=Edge |
| Robots | noindex,nofollow |
| Viewport | width=device-width,initial-scale=1 |
| Content-security-policy | default-src 'none'; script-src 'nonce-hev3JgjUfIZxotkUDbeocS' 'unsafe-eval' https://challenges.cloudflare.com; script-src-attr 'none'; style-src 'unsafe-inline'; img-src 'self' https://challenges.cloudflare.com; connect-src 'self' https://challenges.cloudflare.com; frame-src 'self' https://challenges.cloudflare.com blob:; child-src 'self' https://challenges.cloudflare.com blob:; worker-src blob:; form-action http: https:; base-uri 'self' |
| Refresh | 360 |
Date Wed, 22 Jul 2026 23:49:01 GMT
Content-type text/html; charset=UTF-8
Accept-ch Sec-CH-UA-Bitness, Sec-CH-UA-Arch, Sec-CH-UA-Full-Version, Sec-CH-UA-Mobile, Sec-CH-UA-Model, Sec-CH-UA-Platform-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Platform, Sec-CH-UA, UA-Bitness, UA-Arch, UA-Full-Version, UA-Mobile, UA-Model, UA-Platform-Version, UA-Platform, UA
Cf-mitigated challenge
Content-security-policy default-src 'none'; script-src 'nonce-hev3JgjUfIZxotkUDbeocS' 'unsafe-eval' https://challenges.cloudflare.com; script-src-attr 'none'; style-src 'unsafe-inline'; img-src 'self' https://challenges.cloudflare.com; connect-src 'self' https://challenges.cloudflare.com; frame-src 'self' https://challenges.cloudflare.com blob:; child-src 'self' https://challenges.cloudflare.com blob:; worker-src blob:; form-action http: https:; base-uri 'self'
Server cloudflare
Critical-ch Sec-CH-UA-Bitness, Sec-CH-UA-Arch, Sec-CH-UA-Full-Version, Sec-CH-UA-Mobile, Sec-CH-UA-Model, Sec-CH-UA-Platform-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Platform, Sec-CH-UA, UA-Bitness, UA-Arch, UA-Full-Version, UA-Mobile, UA-Model, UA-Platform-Version, UA-Platform, UA
Cross-origin-embedder-policy require-corp
Cross-origin-opener-policy same-origin
Cross-origin-resource-policy same-origin
Origin-agent-cluster ?1
Permissions-policy accelerometer=(),camera=(),clipboard-read=(),clipboard-write=(),geolocation=(),gyroscope=(),hid=(),magnetometer=(),microphone=(),payment=(),publickey-credentials-get=(),screen-wake-lock=(),serial=(),sync-xhr=(),usb=(),xr-spatial-tracking=*
Referrer-policy same-origin
Server-timing chlray;desc="a1f656e97e507a75"
X-content-type-options nosniff
X-frame-options SAMEORIGIN
Vary accept-encoding
Set-cookie __cf_bm=MXUmdbXZdxY9eu_3iQ7vgexCudh6L6A84q2TnH8Ozd4-1784764141.0403054-1.0.1.1-.LsOA8ouCvra8_x4NKlWYLXUqzV9ZPeBs1V6Jq9Oe_dvpsbu48mhERdJMrRsGVYMe47tpx8iUAIWlxjol8nrbmxf6gZc170mUHJOwYVQtC77_DgxOFmC5QM6tvRLjs0Q; HttpOnly; SameSite=None; Secure; Path=/; Domain=www.searspartsdirect.com; Expires=Thu, 23 Jul 2026 00:19:01 GMT
Expect-ct max-age=86400, enforce
X-xss-protection 1; mode=block
Content-security-policy-report-only default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' cdn.jsdelivr.net js.stripe.com *.criteo.com *.simonsignal.com www.facebook.com connect.facebook.net bat.bing.com *.clarity.ms *.vibe.co www.google-analytics.com cdn.cookielaw.org *.optimizely.com cdnjs.cloudflare.com cdn.debugbear.com googleads.g.doubleclick.net d229tanlyij0i7.cloudfront.net d3cv1fywnihry0.cloudfront.net a61aa9fd029d.cdn4.forter.com js-agent.newrelic.com ui.powerreviews.com payment.searshomeservices.com tags.fullcontact.com www.googletagmanager.com www.paypal.com cdn.id5-sync.com mpsnare.iesnare.com d-code.liadm.com 8quntm5h1h.execute-api.us-east-1.amazonaws.com; frame-src 'self' js.stripe.com payment.searshomeservices.com offers.searshomeservices.com www.googletagmanager.com i.liadm.com gum.criteo.com gumi.criteo.com www.paypal.com c.searspartsdirect.com www.facebook.com connect.facebook.net a25563730275.cdn.optimizely.com; connect-src * data: blob: 'unsafe-inline'; img-src * data: blob: 'unsafe-inline'; media-src * data: blob: 'unsafe-inline'; style-src * data: blob: 'unsafe-inline'; font-src * data: blob: 'unsafe-inline'; worker-src * data: blob: 'unsafe-inline'; base-uri 'self'; form-action 'self' www.facebook.com; frame-ancestors 'self'; report-to report-endpoint;
Reporting-endpoints report-endpoint="https://api.searspartsdirect.com/report-uri"
Strict-transport-security max-age=63072000; includeSubdomains; preload
X-bot-score 1
X-verified-bot false
Content-encoding gzip
Cf-ray a1f656e97e507a75-CDG
Alt-svc h3=":443"; ma=86400