Technical Information
| HTTP Status Code | 403 |
| HTTP Version | HTTP/1.1 |
| HTTPS | ✔ Available |
| IP Address | 3.33.146.110 |
| Server Software | nginx |
| CDN | CDN (MISS) |
| Compression | gzip |
|
🚫 🟡 HTTP 403 Error | The server returned a 403 error. Check the access configuration. |
|
🕐 🟡 Slow Response (1269 ms) | Response time exceeds 1 second. Consider optimizing the server or using caching. |
HTTP Status Code 403
HTTP Version HTTP/1.1
HTTPS ✔ Available
IP Address 3.33.146.110
Server Software nginx
CDN CDN (MISS)
Compression gzip
🚫 🟡 HTTP 403 Error The server returned a 403 error. Check the access configuration.
🕐 🟡 Slow Response (1269 ms) Response time exceeds 1 second. Consider optimizing the server or using caching.
Redirect Chain
| # | URL | HTTP Status Code | Status |
| 1 | https://fsb-tcfd.org:443 | 301 | HTTP/2 301 |
| 2 | https://www.fsb-tcfd.org/ | 403 | HTTP/2 403 |
#1 URL https://fsb-tcfd.org:443
HTTP Status Code 301
Status HTTP/2 301
#2 URL https://www.fsb-tcfd.org/
HTTP Status Code 403
Status HTTP/2 403
Performance
| DNS Lookup | 39 ms |
| TCP Connect | 40.2 ms |
| TLS Handshake | 12 ms |
| Time To First Byte (TTFB) | 1268.1 ms |
| Content Download | 0.4 ms |
| Total Response Time | 1268.5 ms |
DNS Lookup 39 ms
TCP Connect 40.2 ms
TLS Handshake 12 ms
Time To First Byte (TTFB) 1268.1 ms
Content Download 0.4 ms
Total Response Time 1268.5 ms
Security
| HTTPS | ✔ Enabled |
| HSTS | ✔ max-age=31557600 |
| CSP | ✔ Configured |
| X-Frame-Options | ✔ SAMEORIGIN |
| X-Content-Type-Options | ✔ nosniff |
| Referrer Policy | no-referrer-when-downgrade |
| HTTP/2 | ⚠ HTTP/1.1 |
HTTPS ✔ Enabled
HSTS ✔ max-age=31557600
CSP ✔ Configured
X-Frame-Options ✔ SAMEORIGIN
X-Content-Type-Options ✔ nosniff
Referrer Policy no-referrer-when-downgrade
HTTP/2 ⚠ HTTP/1.1
SEO Quick Check
| Title | Access to this page has been denied |
| Meta Description | px-captcha |
Title Access to this page has been denied
Meta Description px-captcha
Detected Technologies
| Technology | Google Analytics Nginx |
Technology Google Analytics Nginx
HTTP Headers
| Content-type | text/html;charset=UTF-8 |
| Server | nginx |
| Set-cookie | _pxhd=1029f18788d658e5094ca9ea156bb91e7de96324c6aa75cc333885738fd3d7d3:2df978af-9cbc-11f1-82e6-0c72c2c187cf; expires=Fri, 20-Aug-2027 23:25:46 GMT; Max-Age=31557600; path=/ |
| Content-security-policy-report-only | default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval'; style-src 'self' 'unsafe-inline'; img-src 'self' data: blob:; font-src 'self' data:; connect-src 'self' wss:; media-src 'self' blob:; object-src 'none'; frame-ancestors 'self'; base-uri 'self'; upgrade-insecure-requests; report-uri /csp-report; |
| X-frame-options | SAMEORIGIN |
| X-xss-protection | 1; mode=block |
| X-content-type-options | nosniff |
| Referrer-policy | no-referrer-when-downgrade |
| Content-security-policy | default-src 'self' http: https: data: blob: wss: 'unsafe-inline' 'unsafe-eval' |
| Content-encoding | gzip |
| Accept-ranges | bytes |
| Date | Thu, 20 Aug 2026 17:25:46 GMT |
| Via | 1.1 varnish |
| X-served-by | cache-par-lfpb1150052-PAR |
| X-cache | MISS |
| X-cache-hits | 0 |
| X-timer | S1787246745.317601,VS0,VE1214 |
| Vary | Accept-Encoding |
| Strict-transport-security | max-age=31557600 |
Meta Tags
| Viewport | width=device-width, initial-scale=1 |
| Description | px-captcha |
Content-type text/html;charset=UTF-8
Server nginx
Set-cookie _pxhd=1029f18788d658e5094ca9ea156bb91e7de96324c6aa75cc333885738fd3d7d3:2df978af-9cbc-11f1-82e6-0c72c2c187cf; expires=Fri, 20-Aug-2027 23:25:46 GMT; Max-Age=31557600; path=/
Content-security-policy-report-only default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval'; style-src 'self' 'unsafe-inline'; img-src 'self' data: blob:; font-src 'self' data:; connect-src 'self' wss:; media-src 'self' blob:; object-src 'none'; frame-ancestors 'self'; base-uri 'self'; upgrade-insecure-requests; report-uri /csp-report;
X-frame-options SAMEORIGIN
X-xss-protection 1; mode=block
X-content-type-options nosniff
Referrer-policy no-referrer-when-downgrade
Content-security-policy default-src 'self' http: https: data: blob: wss: 'unsafe-inline' 'unsafe-eval'
Content-encoding gzip
Accept-ranges bytes
Date Thu, 20 Aug 2026 17:25:46 GMT
Via 1.1 varnish
X-served-by cache-par-lfpb1150052-PAR
X-cache MISS
X-cache-hits 0
X-timer S1787246745.317601,VS0,VE1214
Vary Accept-Encoding
Strict-transport-security max-age=31557600