Server | nginx |
Content-Type | text/html; charset=UTF-8 |
Connection | keep-alive |
Referrer-Policy | no-referrer |
Vary | Accept-Encoding |
Content-Encoding | gzip |
Host-Header | 192fc2e7e50945beb8231a492d6a8024 |
X-Content-Type-Options | nosniff |
X-Frame-Options | SAMEORIGIN |
X-XSS-Protection | 1; mode=block |
Strict-Transport-Security | max-age=31536000; includeSubDomains; preload |
Content-Security-Policy | default-src 'self'; style-src 'self' 'unsafe-inline' *.jsdelivr.net rgsharedweb.s3.amazonaws.com *.cloudflare.com *.bootstrapcdn.com *.googleapis.com; script-src 'unsafe-inline' 'unsafe-eval' 'self' *.jsdelivr.net *.callrail.com *.thebrighttag.com *.btstatic.com *.cloudflare.com *.stripe.com *.google.com *.gstatic.com *.googleapis.com *.google-analytics.com; img-src 'self' data: *.w.org *.gravatar.com gravityforms.s3.amazonaws.com s3.amazonaws.com *.google-analytics.com; font-src 'self' data: *.jsdelivr.net *.gstatic.com *.bootstrapcdn.com; frame-src 'self' *.youtube.com *.google.com *.stripe.com |
X-Content-Security-Policy | default-src 'self'; style-src 'self' 'unsafe-inline' *.jsdelivr.net rgsharedweb.s3.amazonaws.com *.cloudflare.com *.bootstrapcdn.com *.googleapis.com; script-src 'unsafe-inline' 'unsafe-eval' 'self' *.jsdelivr.net *.callrail.com *.thebrighttag.com *.btstatic.com *.cloudflare.com *.stripe.com *.google.com *.gstatic.com *.googleapis.com *.google-analytics.com; img-src 'self' data: *.w.org *.gravatar.com gravityforms.s3.amazonaws.com s3.amazonaws.com *.google-analytics.com; font-src 'self' data: *.jsdelivr.net *.gstatic.com *.bootstrapcdn.com; frame-src 'self' *.youtube.com *.google.com *.stripe.com |
X-Proxy-Cache | MISS |