Technical Information
| HTTP Status Code | 200 |
| HTTP Version | HTTP/1.1 |
| HTTPS | ✔ Available |
| IP Address | 96.16.248.170 |
| Compression | gzip |
|
🔒 🟡 Mixed Content (2 HTTP resources) | The page is served over HTTPS but loads 2 resource(s) over HTTP. This may be blocked in modern browsers. |
|
ℹ 🔵 Missing X-Frame-Options | The site can be embedded in iframes by third parties (clickjacking risk). |
HTTP Status Code 200
HTTP Version HTTP/1.1
HTTPS ✔ Available
IP Address 96.16.248.170
Compression gzip
🔒 🟡 Mixed Content (2 HTTP resources) The page is served over HTTPS but loads 2 resource(s) over HTTP. This may be blocked in modern browsers.
ℹ 🔵 Missing X-Frame-Options The site can be embedded in iframes by third parties (clickjacking risk).
Redirect Chain
| # | URL | HTTP Status Code | Status |
| 1 | https://mlssoccer.com:443 | 302 | HTTP/2 302 |
| 2 | https://www.mlssoccer.com/ | 200 | HTTP/2 200 |
#1 URL https://mlssoccer.com:443
HTTP Status Code 302
Status HTTP/2 302
#2 URL https://www.mlssoccer.com/
HTTP Status Code 200
Status HTTP/2 200
Performance
| DNS Lookup | 21.6 ms |
| TCP Connect | 23.3 ms |
| TLS Handshake | 30 ms |
| Time To First Byte (TTFB) | 103 ms |
| Content Download | 3.3 ms |
| Total Response Time | 106.3 ms |
DNS Lookup 21.6 ms
TCP Connect 23.3 ms
TLS Handshake 30 ms
Time To First Byte (TTFB) 103 ms
Content Download 3.3 ms
Total Response Time 106.3 ms
Security
| HTTPS | ✔ Enabled |
| HSTS | ✔ max-age=15768000 ; includeSubDomains |
| CSP | ✔ Configured |
| X-Frame-Options | ⚠ Not configured |
| X-Content-Type-Options | ✔ nosniff |
| HTTP/2 | ⚠ HTTP/1.1 |
HTTPS ✔ Enabled
HSTS ✔ max-age=15768000 ; includeSubDomains
CSP ✔ Configured
X-Frame-Options ⚠ Not configured
X-Content-Type-Options ✔ nosniff
HTTP/2 ⚠ HTTP/1.1
SEO Quick Check
| Title | MLSsoccer.com - The Official Site of Major League Soccer |
| Canonical | https://www.mlssoccer.com/ |
Title MLSsoccer.com - The Official Site of Major League Soccer
Canonical https://www.mlssoccer.com/
Detected Technologies
| Technology | Google Analytics Google Tag Manager |
Technology Google Analytics Google Tag Manager
HTTP Headers
| Content-type
| text/html |
| Content-encoding
| gzip |
| Content-length
| 55982 |
| Cache-control
| max-age=102 |
| Date
| Sat, 29 Aug 2026 21:45:33 GMT |
| Vary
| Accept-Encoding |
| Content-security-policy
| default-src blob: * 'unsafe-inline' 'unsafe-eval'; script-src * blob: 'unsafe-inline' 'unsafe-eval'; connect-src * 'unsafe-inline'; img-src * data: blob: 'unsafe-inline'; frame-src *; style-src * 'unsafe-inline'; font-src * data: 'unsafe-inline'; |
| X-content-type-options
| nosniff |
| Access-control-allow-credentials
| true |
| Access-control-allow-headers
| X-UserId, authorization, accept, If-None-Match, If-Modified-Since, Content-Type, access-control-allow-origin |
| Access-control-allow-methods
| GET,POST,DELETE,PUT,OPTIONS |
| Access-control-allow-origin
| * |
| Strict-transport-security
| max-age=15768000 ; includeSubDomains |
Meta Tags
| Viewport | width=device-width, initial-scale=1.0 |
Content-type text/html
Content-encoding gzip
Content-length 55982
Cache-control max-age=102
Date Sat, 29 Aug 2026 21:45:33 GMT
Vary Accept-Encoding
Content-security-policy default-src blob: * 'unsafe-inline' 'unsafe-eval'; script-src * blob: 'unsafe-inline' 'unsafe-eval'; connect-src * 'unsafe-inline'; img-src * data: blob: 'unsafe-inline'; frame-src *; style-src * 'unsafe-inline'; font-src * data: 'unsafe-inline';
X-content-type-options nosniff
Access-control-allow-credentials true
Access-control-allow-headers X-UserId, authorization, accept, If-None-Match, If-Modified-Since, Content-Type, access-control-allow-origin
Access-control-allow-methods GET,POST,DELETE,PUT,OPTIONS
Access-control-allow-origin *
Strict-transport-security max-age=15768000 ; includeSubDomains