Technical Information
| HTTP Status Code | 200 |
| HTTP Version | HTTP/1.1 |
| HTTPS | ✔ Available |
| IP Address | 100.58.85.137 |
| Server Software | CloudFront |
| CDN | CDN (Hit from cloudfront) |
| Compression | gzip |
|
ℹ 🔵 Missing Content Security Policy | CSP is not configured. It helps prevent XSS attacks and content injection. |
HTTP Status Code 200
HTTP Version HTTP/1.1
HTTPS ✔ Available
IP Address 100.58.85.137
Server Software CloudFront
CDN CDN (Hit from cloudfront)
Compression gzip
ℹ 🔵 Missing Content Security Policy CSP is not configured. It helps prevent XSS attacks and content injection.
Redirect Chain
| # | URL | HTTP Status Code | Status |
| 1 | https://sesamestreet.org:443 | 302 | HTTP/2 302 |
| 2 | https://www.sesamestreet.org/ | 200 | HTTP/2 200 |
#1 URL https://sesamestreet.org:443
HTTP Status Code 302
Status HTTP/2 302
#2 URL https://www.sesamestreet.org/
HTTP Status Code 200
Status HTTP/2 200
Performance
| DNS Lookup | 5.2 ms |
| TCP Connect | 6.3 ms |
| TLS Handshake | 6.1 ms |
| Time To First Byte (TTFB) | 34.2 ms |
| Content Download | 0.2 ms |
| Total Response Time | 34.4 ms |
DNS Lookup 5.2 ms
TCP Connect 6.3 ms
TLS Handshake 6.1 ms
Time To First Byte (TTFB) 34.2 ms
Content Download 0.2 ms
Total Response Time 34.4 ms
Security
| HTTPS | ✔ Enabled |
| HSTS | ✔ max-age=2592000 |
| CSP | ⚠ Not configured |
| X-Frame-Options | ✔ sameorigin |
| X-Content-Type-Options | ✔ nosniff |
| Referrer Policy | same-origin |
| HTTP/2 | ⚠ HTTP/1.1 |
HTTPS ✔ Enabled
HSTS ✔ max-age=2592000
CSP ⚠ Not configured
X-Frame-Options ✔ sameorigin
X-Content-Type-Options ✔ nosniff
Referrer Policy same-origin
HTTP/2 ⚠ HTTP/1.1
Detected Technologies
| Technology | Drupal React Google Analytics Google Tag Manager Cloudflare Node.js Next.js |
Technology Drupal React Google Analytics Google Tag Manager Cloudflare Node.js Next.js
HTTP Headers
| Server
| CloudFront |
| Content-type
| text/html; charset=utf-8 |
| Date
| Thu, 23 Jul 2026 10:49:46 GMT |
| Content-encoding
| gzip |
| Access-control-allow-credentials
| true |
| Access-control-allow-origin
| * |
| Access-control-allow-methods
| GET,POST |
| Access-control-allow-headers
| X-CSRF-Token, X-Requested-With, Accept, Accept-Version, Content-Length, Content-MD5, Content-Type, Date, X-Api-Version |
| X-nextjs-cache
| HIT |
| Cache-control
| s-maxage=600, stale-while-revalidate=31535400 |
| X-powered-by
| Next.js |
| Etag
| "hhiks4ycn5xo7" |
| Vary
| Accept-Encoding |
| Via
| 1.1 42501186135af3199ef312857c031b5a.cloudfront.net (CloudFront) |
| Age
| 7667 |
| Strict-transport-security
| max-age=2592000 |
| X-content-type-options
| nosniff |
| X-frame-options
| sameorigin |
| X-xss-protection
| 1; mode=block |
| Referrer-policy
| same-origin |
| X-cache
| Hit from cloudfront |
| X-amz-cf-pop
| CDG50-P6 |
| X-amz-cf-id
| Lb5R2-3XqxggZMJC5ymtjGsgFDgjzXZFvNsSYov6uIu0zsorJPxOkA== |
Meta Tags
| Viewport | width=device-width |
Server CloudFront
Content-type text/html; charset=utf-8
Date Thu, 23 Jul 2026 10:49:46 GMT
Content-encoding gzip
Access-control-allow-credentials true
Access-control-allow-origin *
Access-control-allow-methods GET,POST
Access-control-allow-headers X-CSRF-Token, X-Requested-With, Accept, Accept-Version, Content-Length, Content-MD5, Content-Type, Date, X-Api-Version
X-nextjs-cache HIT
Cache-control s-maxage=600, stale-while-revalidate=31535400
X-powered-by Next.js
Etag "hhiks4ycn5xo7"
Vary Accept-Encoding
Via 1.1 42501186135af3199ef312857c031b5a.cloudfront.net (CloudFront)
Age 7667
Strict-transport-security max-age=2592000
X-content-type-options nosniff
X-frame-options sameorigin
X-xss-protection 1; mode=block
Referrer-policy same-origin
X-cache Hit from cloudfront
X-amz-cf-pop CDG50-P6
X-amz-cf-id Lb5R2-3XqxggZMJC5ymtjGsgFDgjzXZFvNsSYov6uIu0zsorJPxOkA==