Technical Information
| HTTP Status Code | 403 |
| HTTP Version | HTTP/1.1 |
| HTTPS | ✔ Available |
| IP Address | 172.64.153.227 |
| Server Software | cloudflare |
| CDN | Cloudflare |
| Compression | gzip |
|
🚫 🟡 HTTP 403 Error | The server returned a 403 error. Check the access configuration. |
|
ℹ 🔵 Missing Content Security Policy | CSP is not configured. It helps prevent XSS attacks and content injection. |
HTTP Status Code 403
HTTP Version HTTP/1.1
HTTPS ✔ Available
IP Address 172.64.153.227
Server Software cloudflare
CDN Cloudflare
Compression gzip
🚫 🟡 HTTP 403 Error The server returned a 403 error. Check the access configuration.
ℹ 🔵 Missing Content Security Policy CSP is not configured. It helps prevent XSS attacks and content injection.
Performance
| DNS Lookup | 22.8 ms |
| TCP Connect | 24.7 ms |
| TLS Handshake | 8.2 ms |
| Time To First Byte (TTFB) | 45.3 ms |
| Content Download | 0.2 ms |
| Total Response Time | 45.5 ms |
DNS Lookup 22.8 ms
TCP Connect 24.7 ms
TLS Handshake 8.2 ms
Time To First Byte (TTFB) 45.3 ms
Content Download 0.2 ms
Total Response Time 45.5 ms
Security
| HTTPS | ✔ Enabled |
| HSTS | ✔ max-age=31536000; includeSubDomains; preload |
| CSP | ⚠ Not configured |
| X-Frame-Options | ✔ SAMEORIGIN |
| X-Content-Type-Options | ✔ nosniff |
| Referrer Policy | same-origin |
| HTTP/2 | ⚠ HTTP/1.1 |
HTTPS ✔ Enabled
HSTS ✔ max-age=31536000; includeSubDomains; preload
CSP ⚠ Not configured
X-Frame-Options ✔ SAMEORIGIN
X-Content-Type-Options ✔ nosniff
Referrer Policy same-origin
HTTP/2 ⚠ HTTP/1.1
SEO Quick Check
Title thredUP
Detected Technologies
Technology Cloudflare
HTTP Headers
| Date | Thu, 23 Jul 2026 19:59:18 GMT |
| Content-type | text/html; charset=UTF-8 |
| Cache-control | private, max-age=0, no-store, no-cache, must-revalidate, post-check=0, pre-check=0 |
| Expires | Thu, 01 Jan 1970 00:00:01 GMT |
| Referrer-policy | same-origin |
| X-frame-options | SAMEORIGIN |
| Strict-transport-security | max-age=31536000; includeSubDomains; preload |
| X-content-type-options | nosniff |
| Vary | accept-encoding |
| Set-cookie | __cf_bm=TRQSR9l1Xdk7s_Di39s1n6ZMUX_KhIa0XlLYwc7D7XY-1784836758.7731998-1.0.1.1-g_WWK4CjTx3etkch5qL76KHWeYV3Xr5Pc2RtZJiE7QSH1ZxHN.rGtC6eHEmwY1TdAaqOTh4E8ltZLYTa84Nmw8oDcE7wCcZW97Yo7Xbo6k28q9P0pAkfLZQpBOyEsQa4ClEbIPTQiJx2ErXjc1eciQ; HttpOnly; SameSite=None; Secure; Path=/; Domain=thredup.com; Expires=Thu, 23 Jul 2026 20:29:18 GMT |
| Content-encoding | gzip |
| Server | cloudflare |
| Cf-ray | a1fd43ce595a154c-CDG |
| Alt-svc | h3=":443"; ma=86400 |
Date Thu, 23 Jul 2026 19:59:18 GMT
Content-type text/html; charset=UTF-8
Cache-control private, max-age=0, no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Expires Thu, 01 Jan 1970 00:00:01 GMT
Referrer-policy same-origin
X-frame-options SAMEORIGIN
Strict-transport-security max-age=31536000; includeSubDomains; preload
X-content-type-options nosniff
Vary accept-encoding
Set-cookie __cf_bm=TRQSR9l1Xdk7s_Di39s1n6ZMUX_KhIa0XlLYwc7D7XY-1784836758.7731998-1.0.1.1-g_WWK4CjTx3etkch5qL76KHWeYV3Xr5Pc2RtZJiE7QSH1ZxHN.rGtC6eHEmwY1TdAaqOTh4E8ltZLYTa84Nmw8oDcE7wCcZW97Yo7Xbo6k28q9P0pAkfLZQpBOyEsQa4ClEbIPTQiJx2ErXjc1eciQ; HttpOnly; SameSite=None; Secure; Path=/; Domain=thredup.com; Expires=Thu, 23 Jul 2026 20:29:18 GMT
Content-encoding gzip
Server cloudflare
Cf-ray a1fd43ce595a154c-CDG
Alt-svc h3=":443"; ma=86400