Informations Techniques
| Code de Statut HTTP | 403 |
| Version HTTP | HTTP/1.1 |
| HTTPS | ✔ Disponible |
| Adresse IP | 104.18.34.54 |
| Logiciel Serveur | cloudflare |
| CDN | Cloudflare |
| Compression | gzip |
|
🚫 🟡 Erreur HTTP 403 | Le serveur a retourné une erreur 403. Vérifiez la configuration d'accès. |
Code de Statut HTTP 403
Version HTTP HTTP/1.1
HTTPS ✔ Disponible
Adresse IP 104.18.34.54
Logiciel Serveur cloudflare
CDN Cloudflare
Compression gzip
🚫 🟡 Erreur HTTP 403 Le serveur a retourné une erreur 403. Vérifiez la configuration d'accès.
Chaîne de Redirection
| # | URL | Code de Statut HTTP | Statut |
| 1 | https://searspartsdirect.com:443 | 301 | HTTP/2 301 |
| 2 | https://www.searspartsdirect.com/ | 403 | HTTP/2 403 |
#1 URL https://searspartsdirect.com:443
Code de Statut HTTP 301
Statut HTTP/2 301
#2 URL https://www.searspartsdirect.com/
Code de Statut HTTP 403
Statut HTTP/2 403
Performance
| Résolution DNS | 38.1 ms |
| Connexion TCP | 39.8 ms |
| Négociation TLS | 9.9 ms |
| Temps Jusqu'au Premier Octet (TTFB) | 61.3 ms |
| Téléchargement du Contenu | 0.1 ms |
| Temps de Réponse Total | 61.4 ms |
Résolution DNS 38.1 ms
Connexion TCP 39.8 ms
Négociation TLS 9.9 ms
Temps Jusqu'au Premier Octet (TTFB) 61.3 ms
Téléchargement du Contenu 0.1 ms
Temps de Réponse Total 61.4 ms
Sécurité
| HTTPS | ✔ Activé |
| HSTS | ✔ max-age=63072000; includeSubdomains; preload |
| CSP | ✔ Configuré |
| X-Frame-Options | ✔ SAMEORIGIN |
| X-Content-Type-Options | ✔ nosniff |
| Politique de Référent | same-origin |
| Politique de Permissions | ✔ Configuré |
| HTTP/2 | ⚠ HTTP/1.1 |
HTTPS ✔ Activé
HSTS ✔ max-age=63072000; includeSubdomains; preload
CSP ✔ Configuré
X-Frame-Options ✔ SAMEORIGIN
X-Content-Type-Options ✔ nosniff
Politique de Référent same-origin
Politique de Permissions ✔ Configuré
HTTP/2 ⚠ HTTP/1.1
Vérification SEO Rapide
| Titre | Just a moment... |
| Robots Meta | noindex,nofollow |
Titre Just a moment...
Robots Meta noindex,nofollow
Technologies Détectées
| Technologie | Google Analytics Google Tag Manager Cloudflare Stripe |
Technologie Google Analytics Google Tag Manager Cloudflare Stripe
En-têtes HTTP
| Date | Wed, 22 Jul 2026 21:08:58 GMT |
| Content-type | text/html; charset=UTF-8 |
| Accept-ch | Sec-CH-UA-Bitness, Sec-CH-UA-Arch, Sec-CH-UA-Full-Version, Sec-CH-UA-Mobile, Sec-CH-UA-Model, Sec-CH-UA-Platform-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Platform, Sec-CH-UA, UA-Bitness, UA-Arch, UA-Full-Version, UA-Mobile, UA-Model, UA-Platform-Version, UA-Platform, UA |
| Cf-mitigated | challenge |
| Content-security-policy | default-src 'none'; script-src 'nonce-LWYczQG3RJWxLB3LABTEnB' 'unsafe-eval' https://challenges.cloudflare.com; script-src-attr 'none'; style-src 'unsafe-inline'; img-src 'self' https://challenges.cloudflare.com; connect-src 'self' https://challenges.cloudflare.com; frame-src 'self' https://challenges.cloudflare.com blob:; child-src 'self' https://challenges.cloudflare.com blob:; worker-src blob:; form-action http: https:; base-uri 'self' |
| Server | cloudflare |
| Critical-ch | Sec-CH-UA-Bitness, Sec-CH-UA-Arch, Sec-CH-UA-Full-Version, Sec-CH-UA-Mobile, Sec-CH-UA-Model, Sec-CH-UA-Platform-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Platform, Sec-CH-UA, UA-Bitness, UA-Arch, UA-Full-Version, UA-Mobile, UA-Model, UA-Platform-Version, UA-Platform, UA |
| Cross-origin-embedder-policy | require-corp |
| Cross-origin-opener-policy | same-origin |
| Cross-origin-resource-policy | same-origin |
| Origin-agent-cluster | ?1 |
| Permissions-policy | accelerometer=(),camera=(),clipboard-read=(),clipboard-write=(),geolocation=(),gyroscope=(),hid=(),magnetometer=(),microphone=(),payment=(),publickey-credentials-get=(),screen-wake-lock=(),serial=(),sync-xhr=(),usb=(),xr-spatial-tracking=* |
| Referrer-policy | same-origin |
| Server-timing | chlray;desc="a1f56c7bcd252a44" |
| X-content-type-options | nosniff |
| X-frame-options | SAMEORIGIN |
| Vary | accept-encoding |
| Set-cookie | __cf_bm=EhVpPVRsrR29_ZJhKwVsxJJ3LtFFypYTF.enc30bAMY-1784754538.8429198-1.0.1.1-qPZvKxIV8GfWSG6v3nriUtWWcKT616IEutux5J7LeTfApxUI1r3nOM9fwjiejSHC0vPMvNTTmCfvJi4cpR9UoEDYoEZiB4nXTirvmhH.dz923ABXt3gzovAIL4yU6ziY; HttpOnly; SameSite=None; Secure; Path=/; Domain=www.searspartsdirect.com; Expires=Wed, 22 Jul 2026 21:38:58 GMT |
| Expect-ct | max-age=86400, enforce |
| X-xss-protection | 1; mode=block |
| Content-security-policy-report-only | default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' cdn.jsdelivr.net js.stripe.com *.criteo.com *.simonsignal.com www.facebook.com connect.facebook.net bat.bing.com *.clarity.ms *.vibe.co www.google-analytics.com cdn.cookielaw.org *.optimizely.com cdnjs.cloudflare.com cdn.debugbear.com googleads.g.doubleclick.net d229tanlyij0i7.cloudfront.net d3cv1fywnihry0.cloudfront.net a61aa9fd029d.cdn4.forter.com js-agent.newrelic.com ui.powerreviews.com payment.searshomeservices.com tags.fullcontact.com www.googletagmanager.com www.paypal.com cdn.id5-sync.com mpsnare.iesnare.com d-code.liadm.com 8quntm5h1h.execute-api.us-east-1.amazonaws.com; frame-src 'self' js.stripe.com payment.searshomeservices.com offers.searshomeservices.com www.googletagmanager.com i.liadm.com gum.criteo.com gumi.criteo.com www.paypal.com c.searspartsdirect.com www.facebook.com connect.facebook.net a25563730275.cdn.optimizely.com; connect-src * data: blob: 'unsafe-inline'; img-src * data: blob: 'unsafe-inline'; media-src * data: blob: 'unsafe-inline'; style-src * data: blob: 'unsafe-inline'; font-src * data: blob: 'unsafe-inline'; worker-src * data: blob: 'unsafe-inline'; base-uri 'self'; form-action 'self' www.facebook.com; frame-ancestors 'self'; report-to report-endpoint; |
| Reporting-endpoints | report-endpoint="https://api.searspartsdirect.com/report-uri" |
| Strict-transport-security | max-age=63072000; includeSubdomains; preload |
| X-bot-score | 1 |
| X-verified-bot | false |
| Content-encoding | gzip |
| Cf-ray | a1f56c7bcd252a44-CDG |
| Alt-svc | h3=":443"; ma=86400 |
Balises Meta
| Content-Type | text/html; charset=UTF-8 |
| X-UA-Compatible | IE=Edge |
| Robots | noindex,nofollow |
| Viewport | width=device-width,initial-scale=1 |
| Content-security-policy | default-src 'none'; script-src 'nonce-LWYczQG3RJWxLB3LABTEnB' 'unsafe-eval' https://challenges.cloudflare.com; script-src-attr 'none'; style-src 'unsafe-inline'; img-src 'self' https://challenges.cloudflare.com; connect-src 'self' https://challenges.cloudflare.com; frame-src 'self' https://challenges.cloudflare.com blob:; child-src 'self' https://challenges.cloudflare.com blob:; worker-src blob:; form-action http: https:; base-uri 'self' |
| Refresh | 360 |
Date Wed, 22 Jul 2026 21:08:58 GMT
Content-type text/html; charset=UTF-8
Accept-ch Sec-CH-UA-Bitness, Sec-CH-UA-Arch, Sec-CH-UA-Full-Version, Sec-CH-UA-Mobile, Sec-CH-UA-Model, Sec-CH-UA-Platform-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Platform, Sec-CH-UA, UA-Bitness, UA-Arch, UA-Full-Version, UA-Mobile, UA-Model, UA-Platform-Version, UA-Platform, UA
Cf-mitigated challenge
Content-security-policy default-src 'none'; script-src 'nonce-LWYczQG3RJWxLB3LABTEnB' 'unsafe-eval' https://challenges.cloudflare.com; script-src-attr 'none'; style-src 'unsafe-inline'; img-src 'self' https://challenges.cloudflare.com; connect-src 'self' https://challenges.cloudflare.com; frame-src 'self' https://challenges.cloudflare.com blob:; child-src 'self' https://challenges.cloudflare.com blob:; worker-src blob:; form-action http: https:; base-uri 'self'
Server cloudflare
Critical-ch Sec-CH-UA-Bitness, Sec-CH-UA-Arch, Sec-CH-UA-Full-Version, Sec-CH-UA-Mobile, Sec-CH-UA-Model, Sec-CH-UA-Platform-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Platform, Sec-CH-UA, UA-Bitness, UA-Arch, UA-Full-Version, UA-Mobile, UA-Model, UA-Platform-Version, UA-Platform, UA
Cross-origin-embedder-policy require-corp
Cross-origin-opener-policy same-origin
Cross-origin-resource-policy same-origin
Origin-agent-cluster ?1
Permissions-policy accelerometer=(),camera=(),clipboard-read=(),clipboard-write=(),geolocation=(),gyroscope=(),hid=(),magnetometer=(),microphone=(),payment=(),publickey-credentials-get=(),screen-wake-lock=(),serial=(),sync-xhr=(),usb=(),xr-spatial-tracking=*
Referrer-policy same-origin
Server-timing chlray;desc="a1f56c7bcd252a44"
X-content-type-options nosniff
X-frame-options SAMEORIGIN
Vary accept-encoding
Set-cookie __cf_bm=EhVpPVRsrR29_ZJhKwVsxJJ3LtFFypYTF.enc30bAMY-1784754538.8429198-1.0.1.1-qPZvKxIV8GfWSG6v3nriUtWWcKT616IEutux5J7LeTfApxUI1r3nOM9fwjiejSHC0vPMvNTTmCfvJi4cpR9UoEDYoEZiB4nXTirvmhH.dz923ABXt3gzovAIL4yU6ziY; HttpOnly; SameSite=None; Secure; Path=/; Domain=www.searspartsdirect.com; Expires=Wed, 22 Jul 2026 21:38:58 GMT
Expect-ct max-age=86400, enforce
X-xss-protection 1; mode=block
Content-security-policy-report-only default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' cdn.jsdelivr.net js.stripe.com *.criteo.com *.simonsignal.com www.facebook.com connect.facebook.net bat.bing.com *.clarity.ms *.vibe.co www.google-analytics.com cdn.cookielaw.org *.optimizely.com cdnjs.cloudflare.com cdn.debugbear.com googleads.g.doubleclick.net d229tanlyij0i7.cloudfront.net d3cv1fywnihry0.cloudfront.net a61aa9fd029d.cdn4.forter.com js-agent.newrelic.com ui.powerreviews.com payment.searshomeservices.com tags.fullcontact.com www.googletagmanager.com www.paypal.com cdn.id5-sync.com mpsnare.iesnare.com d-code.liadm.com 8quntm5h1h.execute-api.us-east-1.amazonaws.com; frame-src 'self' js.stripe.com payment.searshomeservices.com offers.searshomeservices.com www.googletagmanager.com i.liadm.com gum.criteo.com gumi.criteo.com www.paypal.com c.searspartsdirect.com www.facebook.com connect.facebook.net a25563730275.cdn.optimizely.com; connect-src * data: blob: 'unsafe-inline'; img-src * data: blob: 'unsafe-inline'; media-src * data: blob: 'unsafe-inline'; style-src * data: blob: 'unsafe-inline'; font-src * data: blob: 'unsafe-inline'; worker-src * data: blob: 'unsafe-inline'; base-uri 'self'; form-action 'self' www.facebook.com; frame-ancestors 'self'; report-to report-endpoint;
Reporting-endpoints report-endpoint="https://api.searspartsdirect.com/report-uri"
Strict-transport-security max-age=63072000; includeSubdomains; preload
X-bot-score 1
X-verified-bot false
Content-encoding gzip
Cf-ray a1f56c7bcd252a44-CDG
Alt-svc h3=":443"; ma=86400