Technical Information
| HTTP Status Code | 403 |
| HTTP Version | HTTP/1.1 |
| HTTPS | ✔ Available |
| IP Address | 104.18.6.234 |
| Server Software | cloudflare |
| CDN | Cloudflare |
| Compression | gzip |
|
🚫 🟡 HTTP 403 Error | The server returned a 403 error. Check the access configuration. |
|
ℹ 🔵 Missing Content Security Policy | CSP is not configured. It helps prevent XSS attacks and content injection. |
|
ℹ 🔵 Missing X-Frame-Options | The site can be embedded in iframes by third parties (clickjacking risk). |
HTTP Status Code 403
HTTP Version HTTP/1.1
HTTPS ✔ Available
IP Address 104.18.6.234
Server Software cloudflare
CDN Cloudflare
Compression gzip
🚫 🟡 HTTP 403 Error The server returned a 403 error. Check the access configuration.
ℹ 🔵 Missing Content Security Policy CSP is not configured. It helps prevent XSS attacks and content injection.
ℹ 🔵 Missing X-Frame-Options The site can be embedded in iframes by third parties (clickjacking risk).
Redirect Chain
| # | URL | HTTP Status Code | Status |
| 1 | https://sepaq.com:443 | 301 | HTTP/1.1 301 Moved Permanently |
| 2 | https://www.sepaq.com/ | 403 | HTTP/1.1 403 Forbidden |
#1 URL https://sepaq.com:443
HTTP Status Code 301
Status HTTP/1.1 301 Moved Permanently
#2 URL https://www.sepaq.com/
HTTP Status Code 403
Status HTTP/1.1 403 Forbidden
Performance
| DNS Lookup | 17.6 ms |
| TCP Connect | 19.4 ms |
| TLS Handshake | 8.7 ms |
| Time To First Byte (TTFB) | 52.2 ms |
| Content Download | 0.2 ms |
| Total Response Time | 52.5 ms |
DNS Lookup 17.6 ms
TCP Connect 19.4 ms
TLS Handshake 8.7 ms
Time To First Byte (TTFB) 52.2 ms
Content Download 0.2 ms
Total Response Time 52.5 ms
Security
| HTTPS | ✔ Enabled |
| HSTS | ✔ max-age=31536000; includeSubDomains; preload |
| CSP | ⚠ Not configured |
| X-Frame-Options | ⚠ Not configured |
| X-Content-Type-Options | ✔ nosniff |
| Referrer Policy | same-origin |
| Permissions Policy | ✔ Configured |
| HTTP/2 | ⚠ HTTP/1.1 |
HTTPS ✔ Enabled
HSTS ✔ max-age=31536000; includeSubDomains; preload
CSP ⚠ Not configured
X-Frame-Options ⚠ Not configured
X-Content-Type-Options ✔ nosniff
Referrer Policy same-origin
Permissions Policy ✔ Configured
HTTP/2 ⚠ HTTP/1.1
SEO Quick Check
| Title | Sépaq - Le plus grand réseau de plein air au Québec |
| Robots Meta | noindex, nofollow |
Title Sépaq - Le plus grand réseau de plein air au Québec
Robots Meta noindex, nofollow
Detected Technologies
| Technology | Google Analytics Cloudflare |
Technology Google Analytics Cloudflare
HTTP Headers
| Date | Wed, 22 Jul 2026 13:07:08 GMT |
| Content-Type | text/html; charset=UTF-8 |
| Transfer-Encoding | chunked |
| Connection | close |
| Accept-Ch | Sec-CH-UA-Bitness, Sec-CH-UA-Arch, Sec-CH-UA-Full-Version, Sec-CH-UA-Mobile, Sec-CH-UA-Model, Sec-CH-UA-Platform-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Platform, Sec-CH-UA, UA-Bitness, UA-Arch, UA-Full-Version, UA-Mobile, UA-Model, UA-Platform-Version, UA-Platform, UA |
| Cf-Mitigated | challenge |
| X-XSS-Protection | 1; mode=block |
| Server | cloudflare |
| Critical-Ch | Sec-CH-UA-Bitness, Sec-CH-UA-Arch, Sec-CH-UA-Full-Version, Sec-CH-UA-Mobile, Sec-CH-UA-Model, Sec-CH-UA-Platform-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Platform, Sec-CH-UA, UA-Bitness, UA-Arch, UA-Full-Version, UA-Mobile, UA-Model, UA-Platform-Version, UA-Platform, UA |
| Cross-Origin-Embedder-Policy | require-corp |
| Cross-Origin-Opener-Policy | same-origin |
| Cross-Origin-Resource-Policy | same-origin |
| Origin-Agent-Cluster | ?1 |
| Permissions-Policy | accelerometer=(),camera=(),clipboard-read=(),clipboard-write=(),geolocation=(),gyroscope=(),hid=(),magnetometer=(),microphone=(),payment=(),publickey-credentials-get=(),screen-wake-lock=(),serial=(),sync-xhr=(),usb=(),xr-spatial-tracking=* |
| Referrer-Policy | same-origin |
| Server-Timing | chlray;desc="a1f2aaa9ea1da105" |
| X-Content-Type-Options | nosniff |
| Vary | accept-encoding |
| Set-cookie | __cf_bm=j8QiqPSGXkI97SGEwjL6G2ZlA03dxDS2tnaQKfG1Auo-1784725628.461888-1.0.1.1-0XVwhF4yMny.3M_Y4Cq.K2ynAg_dWePAar4AYH6MvC8n1cjUsk1HlwqDRg5aQgYIwT4jo5sLACYu49ydfu7cuw44NuH5bkrnW37HwtmgjFJJHkeSO6sGKqB0quqeh6D1; HttpOnly; SameSite=None; Secure; Path=/; Domain=sepaq.com; Expires=Wed, 22 Jul 2026 13:37:08 GMT |
| Strict-transport-security | max-age=31536000; includeSubDomains; preload |
| Content-Encoding | gzip |
| CF-RAY | a1f2aaa9ea1da105-CDG |
| Alt-svc | h3=":443"; ma=86400 |
Meta Tags
| Viewport | width=device-width, initial-scale=1, user-scalable=yes |
| Robots | noindex, nofollow |
| Cleartype | on |
| Refresh | 360 |
Date Wed, 22 Jul 2026 13:07:08 GMT
Content-Type text/html; charset=UTF-8
Transfer-Encoding chunked
Connection close
Accept-Ch Sec-CH-UA-Bitness, Sec-CH-UA-Arch, Sec-CH-UA-Full-Version, Sec-CH-UA-Mobile, Sec-CH-UA-Model, Sec-CH-UA-Platform-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Platform, Sec-CH-UA, UA-Bitness, UA-Arch, UA-Full-Version, UA-Mobile, UA-Model, UA-Platform-Version, UA-Platform, UA
Cf-Mitigated challenge
X-XSS-Protection 1; mode=block
Server cloudflare
Critical-Ch Sec-CH-UA-Bitness, Sec-CH-UA-Arch, Sec-CH-UA-Full-Version, Sec-CH-UA-Mobile, Sec-CH-UA-Model, Sec-CH-UA-Platform-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Platform, Sec-CH-UA, UA-Bitness, UA-Arch, UA-Full-Version, UA-Mobile, UA-Model, UA-Platform-Version, UA-Platform, UA
Cross-Origin-Embedder-Policy require-corp
Cross-Origin-Opener-Policy same-origin
Cross-Origin-Resource-Policy same-origin
Origin-Agent-Cluster ?1
Permissions-Policy accelerometer=(),camera=(),clipboard-read=(),clipboard-write=(),geolocation=(),gyroscope=(),hid=(),magnetometer=(),microphone=(),payment=(),publickey-credentials-get=(),screen-wake-lock=(),serial=(),sync-xhr=(),usb=(),xr-spatial-tracking=*
Referrer-Policy same-origin
Server-Timing chlray;desc="a1f2aaa9ea1da105"
X-Content-Type-Options nosniff
Vary accept-encoding
Set-cookie __cf_bm=j8QiqPSGXkI97SGEwjL6G2ZlA03dxDS2tnaQKfG1Auo-1784725628.461888-1.0.1.1-0XVwhF4yMny.3M_Y4Cq.K2ynAg_dWePAar4AYH6MvC8n1cjUsk1HlwqDRg5aQgYIwT4jo5sLACYu49ydfu7cuw44NuH5bkrnW37HwtmgjFJJHkeSO6sGKqB0quqeh6D1; HttpOnly; SameSite=None; Secure; Path=/; Domain=sepaq.com; Expires=Wed, 22 Jul 2026 13:37:08 GMT
Strict-transport-security max-age=31536000; includeSubDomains; preload
Content-Encoding gzip
CF-RAY a1f2aaa9ea1da105-CDG
Alt-svc h3=":443"; ma=86400