DYNAMIC
843422ae2d509554-DUB
no-cache
keep-alive
gzip
text/html; charset=UTF-8
Wed, 10 Jan 2024 10:11:21 GMT
cloudflare
max-age=31536000; includeSubDomains
h3=":443"; ma=86400
child-src blob: 'self' *.fls.doubleclick.net assets.adfenix.com blob: pay.judopay.com player.vimeo.com *.addthis.com foxtons.na1.echosign.com secure.na1.echosign.com spec.co widget.trustpilot.com www.facebook.com; connect-src 'self' data: *.euw2.pure.cloud wss://webmessaging.euw2.pure.cloud wss://streaming.euw2.pure.cloud *.googlesyndication.com *.foxtons.co.uk *.clarity.ms https://*.google.com https://*.google.co.uk api.adfenix.com bat.bing.com ft.foxtons.co.uk *.addthis.com maps.googleapis.com *.ingest.sentry.io *.crazyegg.com https://*.g.doubleclick.net www.facebook.com *.google-analytics.com *.analytics.google.com https://*.googletagmanager.com; default-src 'self' 'unsafe-eval' 'unsafe-inline' *.foxtons.co.uk *.fls.doubleclick.net *.clarity.ms adservice.google.com analytics.twitter.com assets-tracking.crazyegg.com *.foxtons.co.uk bat.bing.com blob: cdn.jsdelivr.net connect.facebook.net *.cloudfront.net data: fonts.googleapis.com fonts.gstatic.com foxtons-static.global.ssl.fastly.net ft.foxtons.co.uk maps.googleapis.com maps.gstatic.com page-assets.foxtons.co.uk page-videos.foxtons.co.uk pagestates-tracking.crazyegg.com player.vimeo.com script.crazyegg.com spec.co static.ads-twitter.com stats.g.doubleclick.net t.co www.facebook.com www.google-analytics.com www.google.com www.googleoptimize.com www.googletagmanager.com; font-src 'self' data: fonts.gstatic.com cdn.neverbounce.com *.sharepointonline.com page-assets.foxtons.co.uk; form-action 'self' 'unsafe-inline' javascript: bosintegweb bos bostrainweb bidx1.com www.tfl.gov.uk www.facebook.com; frame-ancestors 'self' *.foxtons.co.uk; frame-src 'self' td.doubleclick.net *.adobe.io *.adobe.com biddingagent.bidx1.com biddingagent-ppt.bidx1.com apps.euw2.pure.cloud player.simplecast.com www.instagram.com *.documents.adobe.com *.youtube-nocookie.com *.echocdn.com optimize.google.com www.youtube.com view.pagetiger.com vimeo.com foxtons.fixflo.com *.trendmicro.com tpc.googlesyndication.com *.judopay.com *.foxtons.co.uk widget.trustpilot.com foxtons-uat.fixflo.com *.fls.doubleclick.net assets.adfenix.com my.matterport.com player.vimeo.com *.addthis.com foxtons.na1.echosign.com secure.na1.echosign.com spec.co www.facebook.com; img-src 'self' *.basemaps.cartocdn.com *.yhd.net analytics.twitter.com *.foxtons.co.uk images.unsplash.com *.ytimg.com upload.wikimedia.org connect.facebook.net https://*.google.com https://*.google.co.uk translate.googleapis.com https://*.doubleclick.net https://googleads.g.doubleclick.net *.imgix.net images.twenty7tec.com *.googleapis.com *.foxtons.co.uk api.sfnix.net bat.bing.com web.facebook.com *.bing.com *.clarity.ms data: *.cloudfront.net fo-api.omnitagjs.com foxtons-static.global.ssl.fastly.net i.vimeocdn.com *.ggpht.com *.googleusercontent.com maps.googleapis.com secure.adnxs.com sneak-peek.imgix.net t.co www.facebook.com *.google-analytics.com https://*.analytics.google.com www.googletagmanager.com https://*.googletagmanager.com *.gstatic.com pagead2.googlesyndication.com; media-src data: *.foxtons.co.uk page-videos.foxtons.co.uk; object-src 'self' *.foxtons.co.uk; script-src 'self' 'unsafe-eval' 'unsafe-inline' data: *.foxtons.co.uk *.echosign.com apps.euw2.pure.cloud tpc.googlesyndication.com pixels.omnitagjs.com secure.adnxs.com www.googleadservices.com *.clarity.ms analytics.twitter.com api.sfnix.net bat.bing.com cdn.adfenix.com connect.facebook.net *.cloudfront.net foxtons.na1.echosign.com *.addthis.com *.googleapis.com page-assets.foxtons.co.uk *.addthis.com script.crazyegg.com static.ads-twitter.com v1.addthisedge.com widget.trustpilot.com www.google-analytics.com www.googleoptimize.com www.googletagmanager.com https://*.googletagmanager.com z.moatads.com; script-src-attr 'unsafe-inline'; script-src-elem 'self' 'unsafe-inline' biddingagent.bidx1.com biddingagent-ppt.bidx1.com player.vimeo.com static.cloudflareinsights.com *.echosign.com cdn.neverbounce.com optimize.google.com apps.euw2.pure.cloud ajax.googleapis.com widget.trustpilot.com *.clarity.ms analytics.twitter.com api.sfnix.net bat.bing.com cdn.adfenix.com connect.facebook.net *.cloudfront.net foxtons.na1.echosign.com *.addthis.com maps.googleapis.com page-assets.foxtons.co.uk pixels.omnitagjs.com *.addthis.com script.crazyegg.com secure.adnxs.com static.ads-twitter.com v1.addthisedge.com *.google-analytics.com www.googleadservices.com www.googleoptimize.com tagmanager.google.com *.googlesyndication.com www.googletagmanager.com www.gstatic.com *.moatads.com; style-src 'self' 'unsafe-eval' 'unsafe-inline' biddingagent.bidx1.com cdn.jsdelivr.net fonts.googleapis.com page-assets.foxtons.co.uk; style-src-attr 'unsafe-inline'; style-src-elem 'self' 'unsafe-inline' *.gstatic.com *.google-analytics.com *.google.com biddingagent.bidx1.com biddingagent-ppt.bidx1.com pwm-image.trendmicro.com apps.euw2.pure.cloud tpc.googlesyndication.com cdn.jsdelivr.net fonts.googleapis.com page-assets.foxtons.co.uk; worker-src blob: 'self'
accelerometer=(), autoplay=(self "https://www.foxtons.co.uk" "https://player.vimeo.com"), camera=(), cross-origin-isolated=(), display-capture=(), encrypted-media=(), fullscreen=(self "https://www.foxtons.co.uk" "https://player.vimeo.com"), geolocation=(self "https://*.foxtons.co.uk"), gyroscope=(), magnetometer=(), microphone=(self "https://*.foxtons.co.uk"), midi=(), payment=("https://pay.judopay.com" "https://www.judopay.com"), picture-in-picture=(), publickey-credentials-get=(), screen-wake-lock=(), sync-xhr=(), usb=(), web-share=(), xr-spatial-tracking=()
strict-origin-when-cross-origin
Accept-Encoding
nosniff
SAMEORIGIN
|