connection: |
close |
content-length: |
200613 |
pragma: |
cache |
expires: |
Wed, 01 Oct 2025 12:31:37 GMT |
report-to: |
{"group":"report-endpoint","max_age":10886400,"endpoints":[{"url":"https:\/\/www.headcovers.com"}]} |
content-security-policy: |
font-src *.yotpo.com *.gstatic.com *.klevu.com *.googletagmanager.com *.headcovers.com *.userway.org *.hotjar.com *.paypalobjects.com *.klaviyo.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.fontawesome.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.yotpo.com *.facebook.com *.googletagmanager.com *.headcovers.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com *.yotpo.com https://api.boldcommerce.com *.facebook.com *.addthis.com *.headcovers.com *.google.com *.google.com.af *.google.com.ag *.google.com.ai *.google.com.ar *.google.com.au *.google.com.bd *.google.com.bh *.google.com.bn *.google.com.bo *.google.com.br *.google.com.bz *.google.com.co *.google.com.cu *.google.com.cy *.google.com.do *.google.com.ec *.google.com.eg *.google.com.et *.google.com.fj *.google.com.gh *.google.com.gi *.google.com.gt *.google.com.hk *.google.com.jm *.google.com.kh *.google.com.kw *.google.com.lb *.google.com.ly *.google.com.mm *.google.com.mt *.google.com.mx *.google.com.my *.google.com.na *.google.com.ng *.google.com.ni *.google.com.np *.google.com.om *.google.com.pa *.google.com.pe *.google.com.pg *.google.com.ph *.google.com.pk *.google.com.pr *.google.com.py *.google.com.qa *.google.com.sa *.google.com.sb *.google.com.sg *.google.com.sl *.google.com.sv *.google.com.tj *.google.com.tr *.google.com.tw *.google.com.ua *.google.com.uy *.google.com.vc *.google.com.vn *.googletagmanager.com *.paypalobjects.com *.doubleclick.net *.hotjar.com *.userway.org *.freshchat.com *.instagram.com *.vimeo.com saasphoto.com *.commercepartnerhub.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://*.online-metrix.net https://imgs.signifyd.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.yotpo.com https://static.boldcommerce.com https://static.xx.fbcdn.net *.kaltura.com *.userway.org *.facebook.com *.klevu.com *.bing.com *.headcovers.com *.google.com *.google.com.af *.google.com.ag *.google.com.ai *.google.com.ar *.google.com.au *.google.com.bd *.google.com.bh *.google.com.bn *.google.com.bo *.google.com.br *.google.com.bz *.google.com.co *.google.com.cu *.google.com.cy *.google.com.do *.google.com.ec *.google.com.eg *.google.com.et *.google.com.fj *.google.com.gh *.google.com.gi *.google.com.gt *.google.com.hk *.google.com.jm *.google.com.kh *.google.com.kw *.google.com.lb *.google.com.ly *.google.com.mm *.google.com.mt *.google.com.mx *.google.com.my *.google.com.na *.google.com.ng *.google.com.ni *.google.com.np *.google.com.om *.google.com.pa *.google.com.pe *.google.com.pg *.google.com.ph *.google.com.pk *.google.com.pr *.google.com.py *.google.com.qa *.google.com.sa *.google.com.sb *.google.com.sg *.google.com.sl *.google.com.sv *.google.com.tj *.google.com.tr *.google.com.tw *.google.com.ua *.google.com.uy *.google.com.vc *.google.com.vn *.googletagmanager.com *.shopperapproved.com *.gstatic.com *.google-analytics.com *.doubleclick.net *.ytimg.com *.hotjar.com *.clarity.ms *.searchspring.net *.searchspring.io *.cloudfront.net *.trust-guard.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com flagpedia.net https://redchamps.com maps.gstatic.com https://imgs.signifyd.com https://*.online-metrix.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ s7.addthis.com *.yotpo.com https://api.boldcommerce.com https://static.xx.fbcdn.net https://connect.facebook.net https://cdnjs.cloudflare.com https://cashier.boldcommerce.com/assets/experience/flow_sdk.js *.illow.io *.userway.org *.facebook.com *.facebook.net *.headcovers.com *.addthisedge.com *.addthis.com *.moatads.com *.azureedge.net *.google.com *.gstatic.com *.klevu.com *.bing.com *.hotjar.com *.shopperapproved.com *.googletagmanager.com *.google-analytics.com *.googleoptimize.com *.googleadservices.com *.doubleclick.net *.freshchat.com *.instagram.com *.clarity.ms *.searchspring.io *.searchspring.net *.kaltura.com *.chimpstatic.com *.trust-guard.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.avada.io www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://cdn.searchspring.net/intellisuggest/is.min.js maps.googleapis.com https://cdn-scripts.signifyd.com https://imgs.signifyd.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.yotpo.com *.illow.io *.klevu.com *.googletagmanager.com *.google.com *.headcovers.com *.userway.org *.freshchat.com *.hotjar.com *.searchspring.io *.searchspring.net *.shopperapproved.com *.klaviyo.com *.doubleclick.net https://static.klaviyo.com *.fontawesome.com maxcdn.bootstrapcdn.com 'self' 'unsafe-inline'; object-src 'none'; media-src *.adobe.com blob: data: 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com ekr.zdassets.com/ *.yotpo.com https://api.boldcommerce.com https://api.staging.boldcommerce.com https://cashier.boldcommerce.com https://graph.facebook.com https://secure.boldcommerce.com https://secure.staging.boldcommerce.com *.illow.io *.userway.org *.signifyd.com https://bt.signifyd.com:11103 *.klevu.com *.headcovers.com *.core.windows.net *.4-tell.net *.paypal.com *.doubleclick.net *.bing.com *.google-analytics.com *.googletagmanager.com http://*.hotjar.com:* https://*.hotjar.com:* http://*.hotjar.io https://*.hotjar.io wss://*.hotjar.com *.ksearchnet.com *.facebook.com *.clarity.ms *.googleapis.com *.searchspring.io *.kaltura.com *.trust-guard.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://get.geojs.io *.avada.io www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.gstatic.com https://beacon.searchspring.io/beacon https://imgs.signifyd.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://www.headcovers.com; report-to report-endpoint; |
x-content-type-options: |
nosniff |
x-xss-protection: |
1; mode=block |
x-frame-options: |
SAMEORIGIN, SAMEORIGIN |
x-hostname: |
gpc008-node1.us-midwest-1.nxcli.net |
content-type: |
text/html; charset=UTF-8 |
accept-ranges: |
bytes |
age: |
2551 |
date: |
Tue, 01 Oct 2024 13:14:07 GMT |
x-served-by: |
gpc008-node1, cache-chi-kigq8000066-CHI, cache-ams2100131-AMS |
x-cache: |
HIT, HIT |
x-cache-hits: |
1, 0 |
x-timer: |
S1727788448.786650,VS0,VE2 |
cache-control: |
no-store, no-cache, must-revalidate, max-age=0 |
vary: |
Currency,Accept-Encoding,Cookie |
currency: |
EU |
strict-transport-security: |
max-age=31557600 |
|