Server | Apache |
Expires | Thu, 19 Nov 1981 08:52:00 GMT |
Pragma | no-cache |
Referrer-Policy | strict-origin-when-cross-origin |
Strict-Transport-Security | max-age=15768000; includeSubDomains; preload |
Vary | Accept-Encoding |
Content-Encoding | gzip |
X-Content-Type-Options | nosniff |
X-XSS-Protection | 1; mode=block |
X-Frame-Options | sameorigin |
Content-Security-Policy | default-src 'self'; script-src 'self' 'unsafe-eval' 'unsafe-inline' webservice.ntfu.nl maps.googleapis.com cdnjs.cloudflare.com ajax.googleapis.com piwik.fyn.nl www.google-analytics.com connect.facebook.net; style-src 'self' 'unsafe-inline' fonts.googleapis.com fonts.gstatic.com; font-src 'self' fonts.googleapis.com fonts.gstatic.com; img-src 'self' data: maps.googleapis.com maps.gstatic.com csi.gstatic.com piwik.fyn.nl facebook.com www.facebook.com www.google-analytics.com secure.gravatar.com https://graph.facebook.com https://lh6.googleusercontent.com https://scontent.xx.fbcdn.net; child-src 'self' www.enra.nl www.facebook.com; connect-src 'self' https://www.googleapis.com https://graph.facebook.com; object-src 'none'; |
Cache-Control | no-store, no-cache, must-revalidate, private, no-cache, no-store, must-revalidate, proxy-revalidate, no-transform |
Keep-Alive | timeout=5, max=99 |
Connection | Keep-Alive |
Content-Type | text/html; charset=UTF-8 |