Technical Information
| HTTP Status Code | 403 |
| HTTP Version | HTTP/1.1 |
| HTTPS | ✔ Available |
| IP Address | 3.165.136.76 |
| Server Software | DataDome |
| CDN | AWS CloudFront |
| Compression | gzip |
|
🚫 🟡 HTTP 403 Error | The server returned a 403 error. Check the access configuration. |
|
ℹ 🔵 Missing Content Security Policy | CSP is not configured. It helps prevent XSS attacks and content injection. |
|
ℹ 🔵 Missing X-Frame-Options | The site can be embedded in iframes by third parties (clickjacking risk). |
HTTP Status Code 403
HTTP Version HTTP/1.1
HTTPS ✔ Available
IP Address 3.165.136.76
Server Software DataDome
CDN AWS CloudFront
Compression gzip
🚫 🟡 HTTP 403 Error The server returned a 403 error. Check the access configuration.
ℹ 🔵 Missing Content Security Policy CSP is not configured. It helps prevent XSS attacks and content injection.
ℹ 🔵 Missing X-Frame-Options The site can be embedded in iframes by third parties (clickjacking risk).
Performance
| DNS Lookup | 18.5 ms |
| TCP Connect | 19.3 ms |
| TLS Handshake | 4.9 ms |
| Time To First Byte (TTFB) | 286.2 ms |
| Content Download | 0.1 ms |
| Total Response Time | 286.3 ms |
DNS Lookup 18.5 ms
TCP Connect 19.3 ms
TLS Handshake 4.9 ms
Time To First Byte (TTFB) 286.2 ms
Content Download 0.1 ms
Total Response Time 286.3 ms
Security
| HTTPS | ✔ Enabled |
| HSTS | ✔ max-age=300; includeSubDomains |
| CSP | ⚠ Not configured |
| X-Frame-Options | ⚠ Not configured |
| X-Content-Type-Options | ⚠ Not configured |
| HTTP/2 | ⚠ HTTP/1.1 |
HTTPS ✔ Enabled
HSTS ✔ max-age=300; includeSubDomains
CSP ⚠ Not configured
X-Frame-Options ⚠ Not configured
X-Content-Type-Options ⚠ Not configured
HTTP/2 ⚠ HTTP/1.1
SEO Quick Check
Title tripadvisor.ca
HTTP Headers
| Content-type | text/html;charset=utf-8 |
| X-envoy-upstream-service-time | 5 |
| X-dd-b | 2 |
| Set-cookie | TAUnique=%1%enc%3ANJ%2B3Q5JO6sVbk4MXpVXgGZ79dYas2lnMtHL2ashROINdQ0HwVnViSqjcuv3F3uLNNox8JbUSTxk%3D; Max-Age=63072000; HttpOnly; Path=/ |
| Charset | utf-8 |
| Cache-control | no-store, must-revalidate |
| Access-control-allow-credentials | true |
| Access-control-expose-headers | x-dd-b, x-set-cookie |
| Pragma | no-cache |
| Access-control-allow-origin | * |
| X-datadome-cid | AHrlqAAAAAMAMfARRvH2SO0ANC_MAg== |
| Server | DataDome |
| X-datadome | protected |
| Date | Sun, 30 Aug 2026 08:23:02 GMT |
| Accept-ch | Sec-CH-UA,Sec-CH-UA-Mobile,Sec-CH-UA-Platform,Sec-CH-UA-Arch,Sec-CH-UA-Full-Version-List,Sec-CH-UA-Model,Sec-CH-Device-Memory |
| Content-encoding | gzip |
| Strict-transport-security | max-age=300; includeSubDomains |
| X-request-id | 48b4edd9-6296-426f-8c77-47fd34303a29 |
| Vary | Accept-Encoding |
| X-cache | Error from cloudfront |
| Via | 1.1 e4ae90ff37f30536760e8999a38be94a.cloudfront.net (CloudFront) |
| X-amz-cf-pop | CDG52-P3 |
| X-amz-cf-id | qwBUedYAcQvTUBVY6IeqCsUST13VutnfvIfJxhvvnzvzkcP2I1RMPQ== |
Content-type text/html;charset=utf-8
X-envoy-upstream-service-time 5
X-dd-b 2
Set-cookie TAUnique=%1%enc%3ANJ%2B3Q5JO6sVbk4MXpVXgGZ79dYas2lnMtHL2ashROINdQ0HwVnViSqjcuv3F3uLNNox8JbUSTxk%3D; Max-Age=63072000; HttpOnly; Path=/
Charset utf-8
Cache-control no-store, must-revalidate
Access-control-allow-credentials true
Access-control-expose-headers x-dd-b, x-set-cookie
Pragma no-cache
Access-control-allow-origin *
X-datadome-cid AHrlqAAAAAMAMfARRvH2SO0ANC_MAg==
Server DataDome
X-datadome protected
Date Sun, 30 Aug 2026 08:23:02 GMT
Accept-ch Sec-CH-UA,Sec-CH-UA-Mobile,Sec-CH-UA-Platform,Sec-CH-UA-Arch,Sec-CH-UA-Full-Version-List,Sec-CH-UA-Model,Sec-CH-Device-Memory
Content-encoding gzip
Strict-transport-security max-age=300; includeSubDomains
X-request-id 48b4edd9-6296-426f-8c77-47fd34303a29
Vary Accept-Encoding
X-cache Error from cloudfront
Via 1.1 e4ae90ff37f30536760e8999a38be94a.cloudfront.net (CloudFront)
X-amz-cf-pop CDG52-P3
X-amz-cf-id qwBUedYAcQvTUBVY6IeqCsUST13VutnfvIfJxhvvnzvzkcP2I1RMPQ==