Summary
A Concise Overview of the scan result of url https://www.instagram.com/pinkbordeaux.sparkling/
- Document
- HTML
- 2
- StyleSheets
- 2
- Scripts
- 8
- Font
- 0
- Images
- 1
- Links
- 0
- JavaScript Variables
- 32
- Console log messages
- 0
- Network
- Requests
- 13
- Bytes Transferred
- 158.62KB
- Bytes Total
- 905.8KB
- DNS Record
- CNAME Record
- 2
- A Record
- 1
- AAAA Record
- 1
- Technology
- Security
- 1
- Miscellaneous
- 1
Document
Links
The outgoing links identified from the page.
| Link | Text |
|---|
JavaScript Variables
Global JavaScript variables are variables that are defined outside of any function or block scope in JavaScript.
Technology
The technologies identified are present on the scanned URL.
| Name | Description | Detected patterns |
|---|---|---|
| Security | ||
| HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS. | Type: headers Name: strict-transport-security Regex: (?:) | |
| Miscellaneous | ||
HTTP/3 | HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web. | Type: headers Name: alt-svc Regex: h3 |
Performance
The speed and efficiency of the scanned URL loads and displays its content.
- dns
- 1 msGood
- tcp
- 37 msGood
- requestTime
- 423 msNeeds Improvement
- dom
- 1 msGood
DNS Record
A DNS record maps a domain name to an IP address or other resource information.
| Type | Name | Content | DNSSEC |
|---|---|---|---|
| CNAME | www.instagram.com | z-p42-instagram.c10r.instagram.com. | no |
| A | z-p42-instagram.c10r.instagram.com | 57.144.220.34 | no |
| CNAME | www.instagram.com | z-p42-instagram.c10r.instagram.com. | no |
| AAAA | z-p42-instagram.c10r.instagram.com | 2a03:2880:f36e:22:face:b00c:0:4420 | no |
SSL Certificate
An SSL certificate is a digital certificate that verifies the authenticity and encrypts the communication between a website and its visitors.
| Subject | Issue date | Expiry date | Valid |
|---|---|---|---|
www.instagram.com | 3/6/2026 | 3/7/2027 | 1 year 1 day |
static.cdninstagram.com | 3/6/2026 | 3/7/2027 | 1 year 1 day |
HTTP Headers
HTTP Header
An HTTP header is a component of an HTTP request or response that contains additional information about the message being sent or received.
| Name | Value |
|---|---|
| Alt-Svc | h3=":443"; ma=86400 |
| Cache-Control | private, no-cache, no-store, must-revalidate |
| Connection | keep-alive |
| Content-Encoding | zstd |
| Content-Type | text/html; charset="utf-8" |
| Date | Sat, 07 Mar 2026 21:26:20 GMT |
| Expires | Sat, 01 Jan 2000 00:00:00 GMT |
| Pragma | no-cache |
| Strict-Transport-Security | max-age=31536000; preload; includeSubDomains |
| Transfer-Encoding | chunked |
| Vary | Accept-Encoding |
| X-Content-Type-Options | nosniff |
| X-FB-Connection-Quality | EXCELLENT; q=0.9, rtt=5, rtx=0, c=14, mss=1368, tbw=3724, tp=-1, tpl=-1, uplat=87, ullat=0 |
| X-FB-Debug | EsI4lu+ODVKVzIkhzB+ramujGuaLuFvswxTtyt25sCwjS1vsbbE0WKDODBVq2iv7RoWK7Vx+F6bpbW4VFiD55w== |
| X-Frame-Options | DENY |
| X-XSS-Protection | 0 |
| accept-ch | viewport-width,dpr,Sec-CH-Prefers-Color-Scheme,Sec-CH-UA-Full-Version-List,Sec-CH-UA-Platform-Version,Sec-CH-UA-Model |
| accept-ch-lifetime | 4838400 |
| content-security-policy | default-src *.facebook.com *.fbcdn.net *.instagram.com blob: 'wasm-unsafe-eval';script-src *.instagram.com static.cdninstagram.com *.facebook.com *.fbcdn.net *.facebook.net 127.0.0.1:* 'nonce-6ExyIprF' blob: 'self' 'wasm-unsafe-eval' https://*.google-analytics.com https://translate.google.com https://apis.google.com https://accounts.google.com;style-src *.instagram.com static.cdninstagram.com data: blob: 'unsafe-inline' *.fbcdn.net *.facebook.com;connect-src *.instagram.com wss://edge-chat.instagram.com connect.facebook.net *.facebook.com facebook.com *.fbcdn.net *.facebook.net wss://*.facebook.com:* ws://localhost:* blob: *.cdninstagram.com wss://*.instagram.com:* 'self' https://meta.privacy-gateway.cloudflare.com/relay;font-src *.instagram.com static.cdninstagram.com data: *.fbcdn.net *.intern.facebook.com *.facebook.com https://fonts.gstatic.com;img-src *.instagram.com *.facebook.com *.fbcdn.net data: *.cdninstagram.com *.whatsapp.net blob: *.fbsbx.com android-webview-video-poster: *.oculuscdn.com *.giphy.com *.tenor.co *.tenor.com www.googleadservices.com *.doubleclick.net *.google.com *.google.co.uk https://www.gstatic.com https://*.google-analytics.com;media-src *.facebook.com *.fbcdn.net *.instagram.com *.cdninstagram.com *.fbsbx.com data: blob: https://*.giphy.com *.tenor.co *.tenor.com;child-src *.facebook.com *.fbcdn.net *.instagram.com data: blob:;frame-src *.instagram.com *.facebook.com *.fbsbx.com fbsbx.com data: www.googleadservices.com *.doubleclick.net *.google.com *.google.co.uk;manifest-src *.facebook.com *.fbcdn.net *.instagram.com data: blob:;object-src *.facebook.com *.fbcdn.net *.instagram.com data: blob:;block-all-mixed-content;upgrade-insecure-requests; |
| cross-origin-opener-policy | same-origin-allow-popups;report-to="coop_report" |
| cross-origin-resource-policy | same-origin |
| document-policy | force-load-at-top include-js-call-stacks-in-crash-reports |
| origin-agent-cluster | ?1 |
| origin-trial | ArDvqjFKr1fHThlSM8Kkp74sxlOCFTeqYJMXCGqCG/VJmcYlO/0UavmpqPDit2KppDf1THInNpwA36GmtgPOug8AAAB2eyJvcmlnaW4iOiJodHRwczovL3d3dy5pbnN0YWdyYW0uY29tOjQ0MyIsImZlYXR1cmUiOiJDcmFzaFJlcG9ydGluZ1N0b3JhZ2VBUEkiLCJleHBpcnkiOjE3NzY3Mjk2MDAsImlzU3ViZG9tYWluIjp0cnVlfQ== |
| permissions-policy | accelerometer=(self), attribution-reporting=(), autoplay=(), bluetooth=(), camera=(self), ch-device-memory=(), ch-downlink=(), ch-dpr=(), ch-ect=(), ch-rtt=(), ch-save-data=(), ch-ua-arch=(), ch-ua-bitness=(), ch-viewport-height=(), ch-viewport-width=(), ch-width=(), clipboard-read=(), clipboard-write=(self), compute-pressure=(), display-capture=(self), encrypted-media=(), fullscreen=(self), gamepad=(), geolocation=(self), gyroscope=(self), hid=(), idle-detection=(), interest-cohort=(), keyboard-map=(), local-fonts=(), magnetometer=(), microphone=(self), midi=(), otp-credentials=(self), payment=(), picture-in-picture=(self), private-state-token-issuance=(), publickey-credentials-get=(self "https://*.facebook.com" "https://facebook.com"), screen-wake-lock=(), serial=(), shared-storage=(), shared-storage-select-url=(), private-state-token-redemption=(), usb=(), unload=(self), window-management=(), xr-spatial-tracking=();report-to="permissions_policy" |
| report-to | {"max_age":2592000,"endpoints":[{"url":"https:\/\/www.facebook.com\/browser_reporting\/coop\/?minimize=0"}],"group":"coop_report","include_subdomains":true}, {"max_age":259200,"endpoints":[{"url":"https:\/\/www.instagram.com\/error\/ig_web_error_reports\/?device_level=unknown&brsid=7614628180599237718&comet_app_key=7&cpp=C3&cv=1034727812&st=1772918780264"}]}, {"max_age":21600,"endpoints":[{"url":"https:\/\/www.instagram.com\/error\/ig_web_error_reports\/"}],"group":"permissions_policy"} |
| reporting-endpoints | coop_report="https://www.facebook.com/browser_reporting/coop/?minimize=0", default="https://www.instagram.com/error/ig_web_error_reports/?device_level=unknown&brsid=7614628180599237718&comet_app_key=7&cpp=C3&cv=1034727812&st=1772918780264", permissions_policy="https://www.instagram.com/error/ig_web_error_reports/" |
| x-stack | www |
Content Security Policy
Content Security Policy (CSP) is a security mechanism that helps prevent cross-site scripting (XSS) and other code injection attacks by specifying which content sources are allowed to be loaded on a web page.
| Name | Value |
|---|---|
| default-src | *.facebook.com*.fbcdn.net*.instagram.comblob:'wasm-unsafe-eval';script-src*.instagram.comstatic.cdninstagram.com*.facebook.com*.fbcdn.net*.facebook.net127.0.0.1:*'nonce-6ExyIprF'blob:'self''wasm-unsafe-eval'https://*.google-analytics.comhttps://translate.google.comhttps://apis.google.comhttps://accounts.google.com;style-src*.instagram.comstatic.cdninstagram.comdata:blob:'unsafe-inline'*.fbcdn.net*.facebook.com;connect-src*.instagram.comwss://edge-chat.instagram.comconnect.facebook.net*.facebook.comfacebook.com*.fbcdn.net*.facebook.netwss://*.facebook.com:*ws://localhost:*blob:*.cdninstagram.comwss://*.instagram.com:*'self'https://meta.privacy-gateway.cloudflare.com/relay;font-src*.instagram.comstatic.cdninstagram.comdata:*.fbcdn.net*.intern.facebook.com*.facebook.comhttps://fonts.gstatic.com;img-src*.instagram.com*.facebook.com*.fbcdn.netdata:*.cdninstagram.com*.whatsapp.netblob:*.fbsbx.comandroid-webview-video-poster:*.oculuscdn.com*.giphy.com*.tenor.co*.tenor.comwww.googleadservices.com*.doubleclick.net*.google.com*.google.co.ukhttps://www.gstatic.comhttps://*.google-analytics.com;media-src*.facebook.com*.fbcdn.net*.instagram.com*.cdninstagram.com*.fbsbx.comdata:blob:https://*.giphy.com*.tenor.co*.tenor.com;child-src*.facebook.com*.fbcdn.net*.instagram.comdata:blob:;frame-src*.instagram.com*.facebook.com*.fbsbx.comfbsbx.comdata:www.googleadservices.com*.doubleclick.net*.google.com*.google.co.uk;manifest-src*.facebook.com*.fbcdn.net*.instagram.comdata:blob:;object-src*.facebook.com*.fbcdn.net*.instagram.comdata:blob:;block-all-mixed-content;upgrade-insecure-requests |
Cookies
Cookies are small pieces of data stored on a user's web browser to track and remember information about their browsing activity on a website.
| Name | Value | Domain/Path | Expires | Secure | HTTP Only |
|---|---|---|---|---|---|
| csrftoken | [csrftoken redacted] | .instagram.com/ | 4/11/2027, 9:26:20 PM | yes | no |
| datr | _JesaZL2yEU7ZCPNjCKFhbVu | .instagram.com/ | 4/11/2027, 9:26:20 PM | yes | yes |
| ig_did | CF854522-6685-48AA-B9D8-7B4C20E6EC02 | .instagram.com/ | 3/7/2027, 9:26:20 PM | yes | yes |