Content-Type | text/html; charset=utf-8 |
Content-Encoding | gzip |
Vary | Accept-Encoding |
X-Content-Type-Options | nosniff |
X-XSS-Protection | 1; mode=block |
X-Frame-Options | SAMEORIGIN |
Strict-Transport-Security | max-age=157680000; includeSubDomains; |
Cache-Control | no-cache, no-store, must-revalidate, private |
Content-Security-Policy | script-src 'self' 'unsafe-inline' 'unsafe-eval' www.google-analytics.com www.googletagmanager.com stats.g.doubleclick.net newcastle.gi www.newcastle.co.uk online.newcastle.co.uk dax.comscore.eu www.symantec.com t1.stormiq.com *.fls.doubleclick.net staticxx.facebook.net fls.doubleclick.net *.tradedoubler.com ssl.google-analytics.com ajax.googleapis.com apis.google.com platform.twitter.com js.stormiq.com tracking.dc-storm.com uk.sitestat.com www.googleadservices.com use.typekit.net dev.visualwebsitedeveloper.com dev.visualwebsiteoptimizer.com fordeu.d3.sc.omtrdc.net maps.googleapis.com |