max-age=3600
Upgrade, Keep-Alive
default-src 'none'; script-src 'self' 'unsafe-inline' 'unsafe-eval' data: *.rocketcdn.me assets.mailerlite.com static.mailerlite.com cdn.jsdelivr.net *.instagram.com *.stripe.com api.stripe.com js.stripe.com use.fontawesome.com *.facebook.com connect.facebook.net www.googletagservices.com *.googlesyndication.com *.googleadservices.com googleads.g.doubleclick.net adservice.google.com adservice.google.ae adservice.google.al adservice.google.at adservice.google.be adservice.google.bg adservice.google.bs adservice.google.ca adservice.google.ch adservice.google.ci adservice.google.cl adservice.google.co.bw adservice.google.co.cr adservice.google.co.id adservice.google.co.il adservice.google.co.in adservice.google.co.jp adservice.google.co.ke adservice.google.co.kr adservice.google.co.mz adservice.google.co.nz adservice.google.co.th adservice.google.co.tz adservice.google.co.uk adservice.google.co.uz adservice.google.co.ve adservice.google.co.za adservice.google.co.zm adservice.google.co.zw adservice.google.com.ai adservice.google.com.ar adservice.google.com.au adservice.google.com.bd adservice.google.com.bh adservice.google.com.bn adservice.google.com.bo adservice.google.com.br adservice.google.com.co adservice.google.com.cy adservice.google.com.ec adservice.google.com.eg adservice.google.com.et adservice.google.com.fj adservice.google.com.gh adservice.google.com.gi adservice.google.com.gt adservice.google.com.hk adservice.google.com.jm adservice.google.com.kh adservice.google.com.kw adservice.google.com.lb adservice.google.com.mm adservice.google.com.mt adservice.google.com.mx adservice.google.com.my adservice.google.com.ng adservice.google.com.ni adservice.google.com.np adservice.google.com.om adservice.google.com.pa adservice.google.com.pe adservice.google.com.ph adservice.google.com.pk adservice.google.com.pr adservice.google.com.py adservice.google.com.qa adservice.google.com.sa adservice.google.com.sg adservice.google.com.sv adservice.google.com.tr adservice.google.com.tw adservice.google.com.ua adservice.google.com.uy adservice.google.com.vn adservice.google.cz adservice.google.de adservice.google.dk adservice.google.dz adservice.google.ee adservice.google.es adservice.google.fi adservice.google.fr adservice.google.ge adservice.google.gr adservice.google.gy adservice.google.hn adservice.google.hr adservice.google.hu adservice.google.ie adservice.google.im adservice.google.iq adservice.google.is adservice.google.it adservice.google.jo adservice.google.kz adservice.google.li adservice.google.lk adservice.google.lt adservice.google.lu adservice.google.lv adservice.google.md adservice.google.mk adservice.google.mu adservice.google.nl adservice.google.no adservice.google.pl adservice.google.pt adservice.google.ro adservice.google.rs adservice.google.ru adservice.google.se adservice.google.si adservice.google.sk adservice.google.so adservice.google.sr adservice.google.tl adservice.google.tn adservice.google.tt www.google-analytics.com ssl.google-analytics.com stats.g.doubleclick.net ajax.googleapis.com maps.google.com maps.gstatic.com maps.googleapis.com www.googletagmanager.com; style-src 'unsafe-inline' 'self' data: *.rocketcdn.me cdnjs.cloudflare.com fonts.bunny.net maxcdn.bootstrapcdn.com use.fontawesome.com *.facebook.com fonts.googleapis.com maps.googleapis.com; img-src 'self' data: *.rocketcdn.me gravatar.com *.tile.openstreetmap.org track.mailerlite.com *.cdninstagram.com i1.wp.com wpmudev.com *.fbcdn.net *.fbsbx.com *.gstatic.com *.googleapis.com *.facebook.com s.w.org ps.w.org ts.w.org secure.gravatar.com www.gravatar.com *.googlesyndication.com stats.g.doubleclick.net www.google-analytics.com i.ytimg.com www.googletagmanager.com; connect-src 'self' rankmathapi.com api.stripe.com *.stripe.com js.stripe.com fonts.googleapis.com *.facebook.com *.googlesyndication.com googleads.g.doubleclick.net stats.g.doubleclick.net *.google-analytics.com; font-src 'self' data: *.rocketcdn.me cdnjs.cloudflare.com fonts.bunny.net *.bootstrapcdn.com maxcdn.bootstrapcdn.com *.fontawesome.com fonts.gstatic.com; frame-src 'self' data: assets.mailerlite.com static.mailerlite.com *.youtube-nocookie.com *.instagram.com *.spotify.com api.stripe.com *.stripe.com js.stripe.com *.facebook.com *.libsyn.com *.googlesyndication.com googleads.g.doubleclick.net www.youtube.com; child-src 'self' data: *.stripe.com api.stripe.com js.stripe.com www.youtube.com; frame-ancestors 'self' https://stripe.com https://api.stripe.com https://js.stripe.com; upgrade-insecure-requests; block-all-mixed-content; report-uri https://sternmed.de?gdsih-csp-report;
text/html; charset=UTF-8
Wed, 10 Jan 2024 23:18:33 GMT
Thu, 11 Jan 2024 00:18:33 GMT
timeout=2, max=1000
Wed, 10 Jan 2024 23:03:05 GMT
accelerometer=(*), autoplay=(), camera=(), document-domain=(self), encrypted-media=(self), fullscreen=(self), geolocation=(), gyroscope=(), magnetometer=(), microphone=(), midi=(), payment=(), publickey-credentials-get=(), usb=()
same-origin, no-referrer-when-downgrade
Apache
max-age=31536000; includeSubDomains; preload
h2,h2c
Accept-Encoding,User-Agent
nosniff
SAMEORIGIN
1; mode=block; report=https://sternmed.de.de?gdsih-xxp-report;
|