Technical Information
| HTTP Status Code | 200 |
| HTTP Version | HTTP/1.1 |
| HTTPS | ✔ Available |
| IP Address | 34.128.177.10 |
| Server Software | nginx |
| Compression | gzip |
|
ℹ 🔵 Missing Content Security Policy | CSP is not configured. It helps prevent XSS attacks and content injection. |
HTTP Status Code 200
HTTP Version HTTP/1.1
HTTPS ✔ Available
IP Address 34.128.177.10
Server Software nginx
Compression gzip
ℹ 🔵 Missing Content Security Policy CSP is not configured. It helps prevent XSS attacks and content injection.
Redirect Chain
| # | URL | HTTP Status Code | Status |
| 1 | https://luiss.it:443 | 301 | HTTP/2 301 |
| 2 | https://www.luiss.it/ | 301 | HTTP/2 301 |
| 3 | https://www.luiss.it/it | 200 | HTTP/2 200 |
#1 URL https://luiss.it:443
HTTP Status Code 301
Status HTTP/2 301
#2 URL https://www.luiss.it/
HTTP Status Code 301
Status HTTP/2 301
#3 URL https://www.luiss.it/it
HTTP Status Code 200
Status HTTP/2 200
Performance
| DNS Lookup | 0.6 ms |
| TCP Connect | 2.7 ms |
| TLS Handshake | 10 ms |
| Time To First Byte (TTFB) | 17.3 ms |
| Content Download | 0.8 ms |
| Total Response Time | 18.1 ms |
DNS Lookup 0.6 ms
TCP Connect 2.7 ms
TLS Handshake 10 ms
Time To First Byte (TTFB) 17.3 ms
Content Download 0.8 ms
Total Response Time 18.1 ms
Security
| HTTPS | ✔ Enabled |
| HSTS | ✔ max-age=63072000; includeSubDomains; preload |
| CSP | ⚠ Not configured |
| X-Frame-Options | ✔ SAMEORIGIN |
| X-Content-Type-Options | ✔ nosniff |
| Referrer Policy | strict-origin-when-cross-origin |
| Permissions Policy | ✔ Configured |
| HTTP/2 | ⚠ HTTP/1.1 |
HTTPS ✔ Enabled
HSTS ✔ max-age=63072000; includeSubDomains; preload
CSP ⚠ Not configured
X-Frame-Options ✔ SAMEORIGIN
X-Content-Type-Options ✔ nosniff
Referrer Policy strict-origin-when-cross-origin
Permissions Policy ✔ Configured
HTTP/2 ⚠ HTTP/1.1
SEO Quick Check
| Title | Luiss — Libera Università Internazionale degli Studi Sociali |
| Canonical | https://www.luiss.it/it |
Title Luiss — Libera Università Internazionale degli Studi Sociali
Canonical https://www.luiss.it/it
Detected Technologies
| Technology | Drupal Google Analytics Google Tag Manager Nginx |
Technology Drupal Google Analytics Google Tag Manager Nginx
HTTP Headers
| Server
| nginx |
| Content-language
| it |
| X-content-type-options
| nosniff |
| X-frame-options
| SAMEORIGIN |
| Content-security-policy-report-only
| connect-src 'self' public-eur.mkt.dynamics.com formui-usa1.mkt.dynamics.com assets-eur.mkt.dynamics.com https://search.luiss.it; font-src 'self' data: assets-eur.mkt.dynamics.com; frame-src 'self' www.youtube-nocookie.com player.vimeo.com; img-src 'self' data: assets-eur.mkt.dynamics.com; media-src 'self'; object-src 'none'; script-src 'self' 'report-sample' formui-usa1.mkt.dynamics.com; style-src 'self' 'report-sample'; worker-src 'self'; base-uri 'self'; form-action 'self'; frame-ancestors 'self' |
| Strict-transport-security
| max-age=63072000; includeSubDomains; preload |
| Referrer-policy
| strict-origin-when-cross-origin |
| Permissions-policy
| accelerometer=(), camera=(), display-capture=(), geolocation=(), gyroscope=(), magnetometer=(), microphone=(), payment=(), usb=() |
| Cross-origin-opener-policy
| same-origin-allow-popups |
| Cross-origin-embedder-policy
| unsafe-none |
| Cross-origin-resource-policy
| same-site |
| Content-encoding
| gzip |
| Via
| 1.1 google |
| Date
| Thu, 20 Aug 2026 05:10:38 GMT |
| Expires
| Sun, 19 Nov 1978 05:00:00 GMT |
| Cache-control
| max-age=60, public |
| Last-modified
| Tue, 18 Aug 2026 13:55:38 GMT |
| Etag
| W/"1787061338" |
| Content-type
| text/html; charset=utf-8 |
| Vary
| Accept-Encoding |
| Content-length
| 24836 |
| Age
| 6191 |
| X-cdn-cache-status
| stale |
| Alt-svc
| h3=":443"; ma=2592000 |
Meta Tags
| MobileOptimized | width |
| HandheldFriendly | true |
| Viewport | width=device-width, initial-scale=1.0 |
| Msapplication-config | /themes/custom/luiss_corporate/favicon/browserconfig.xml |
| Theme-color | #ffffff |
| Msapplication-TileColor | #ffffff |
| Msapplication-TileImage |  |
Server nginx
Content-language it
X-content-type-options nosniff
X-frame-options SAMEORIGIN
Content-security-policy-report-only connect-src 'self' public-eur.mkt.dynamics.com formui-usa1.mkt.dynamics.com assets-eur.mkt.dynamics.com https://search.luiss.it; font-src 'self' data: assets-eur.mkt.dynamics.com; frame-src 'self' www.youtube-nocookie.com player.vimeo.com; img-src 'self' data: assets-eur.mkt.dynamics.com; media-src 'self'; object-src 'none'; script-src 'self' 'report-sample' formui-usa1.mkt.dynamics.com; style-src 'self' 'report-sample'; worker-src 'self'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'
Strict-transport-security max-age=63072000; includeSubDomains; preload
Referrer-policy strict-origin-when-cross-origin
Permissions-policy accelerometer=(), camera=(), display-capture=(), geolocation=(), gyroscope=(), magnetometer=(), microphone=(), payment=(), usb=()
Cross-origin-opener-policy same-origin-allow-popups
Cross-origin-embedder-policy unsafe-none
Cross-origin-resource-policy same-site
Content-encoding gzip
Via 1.1 google
Date Thu, 20 Aug 2026 05:10:38 GMT
Expires Sun, 19 Nov 1978 05:00:00 GMT
Cache-control max-age=60, public
Last-modified Tue, 18 Aug 2026 13:55:38 GMT
Etag W/"1787061338"
Content-type text/html; charset=utf-8
Vary Accept-Encoding
Content-length 24836
Age 6191
X-cdn-cache-status stale
Alt-svc h3=":443"; ma=2592000