31 Headers

HTTP Security Headers

Status
Strict-Transport-Security
Excellent
max-age=31536000; includeSubDomains; preload
Content-Security-Policy
Basic
default-src; script-src; style-src; +12 more
X-Frame-Options
Good
SAMEORIGIN
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Good
no-referrer-when-downgrade
Permissions-Policy
Present
accelerometer=(*), autoplay=(*), camera=(*), encrypted-media=(*), fullscreen=(*), geolocation=(*), gyroscope=(*), magnetometer=(*), microphone=(*), midi=(*), payment=(*), picture-in-picture=(*), sync-xhr=(*), usb=(*), clipboard-write=(*)
Recommendations
  • Improve CSP by adding more specific directives and removing 'unsafe-inline'

Performance Headers

2 headers
Connection
Performance
keep-alive
Transfer-Encoding
Performance
chunked

Caching Headers

3 headers
Cache-Control
Caching
no-store, no-cache, must-revalidate
Etag
Caching
W/"94ad7d86bc252efd2bf21645db4dba33"
Last-Modified
Caching
Fri, 07 Nov 2025 10:21:18 GMT

Content Headers

1 headers
Content-Type
Content
text/html; charset=UTF-8

Server Headers

1 headers
Server
Server
cloudflare

CORS Headers

0 headers
No CORS headers found

Cookies Headers

1 headers
Set-Cookie
Cookies
_cfuvid=tYnhuPJwM3ksYSRuM6GuilUvgTd8cHi4E12nTWscvvU-1762543519914-0.0.1.1-604800000; path=/; domain=.www.q2.com; HttpOnly; Secure; SameSite=None

Other Headers

16 headers
Alt-Svc
Other
h3=":443"; ma=86400
Cf-Ray
Other
99af37470fb3d6b4-IAD
Content-Security-Policy-Report-Only
Other
default-src 'self'; script-src 'report-sample' 'self' 'unsafe-inline' 'unsafe-eval' *.hubspot.com *.cookielaw.org *.cdntwrk.com *.wistia.com *.wistia.net *.q2.com *.sentry-cdn.com *.clarity.ms *.google.com *.googletagmanager.com *.googleapis.com *.googleadservices.com *.gstatic.com *.hsappstatic.com *.hsappstatic.net *.hubspot.net *.hs-banner.com *.hsadspixel.net *.hs-analytics.com *.hs-analytics.net *.licdn.com *.marketo.net *.marketo.com *.zoominfo.com *.bizible.com *.6sc.co *.qualified.com *.segment.com *.bugcrowd.com *.bugcrowdusercontent.com bugcrowd.com *.jsdeliver.net *.jsdelivr.net *.cloudflare.com *.doubleclick.net *.youtube.com *.hubspotusercontent-na1.net *.pathfactory.com *.zuddl.com 8ab0a26cb0027939bcf5-49c99c3c0c9c98b3365b710757036e1b.ssl.cf5.rackcdn.com *.crazyegg.com *.callrail.com; style-src 'self' *.q2.com 'report-sample' 'unsafe-inline' *.cdntwrk.com *.googleapis.com *.hsappstatic.net *.hubspot.net *.jsdeliver.net *.jsdelivr.net *.marketo.com 7044196.fs1.hubspotusercontent-na1.net 7044196.fs2.hubspotusercontent-na1.net *.hubspotusercontent-na1.net *.pathfactory.com *.googletagmanager.com *.zuddl.com *.qualified.com; object-src 'none'; base-uri 'self'; connect-src 'self' *.mktoresp.com *.hubspotusercontent-na1.net *.google.com *.hubspot.com *.hs-banner.com *.onetrust.com *.cookielaw.org *.wistia.com *.embed-cloudfront.wistia.com *.wistia.net *.6sc.co *.6sense.com *.qualified.com wss://*.qualified.com *.segment.com *.segment.io *.linkedin.com *.google-analytics.com *.clarity.ms *.hubapi.com *.doubleclick.com https://stats.g.doubleclick.net *.zoominfo.com *.adnxs.com *.litix.io *.marketo.com *.doubleclick.net *.youtube.com *.pathfactory.com *.zuddl.com api.prod.zuddl.com *.crazyegg.com *.gonorth.io *.callrail.com *.googleadservices.com; font-src 'self' data: *.gstatic.com *.cdntwrk.com *.wistia.com *.wistia.net 7044196.fs1.hubspotusercontent-na1.net *.pathfactory.com *.zuddl.com; frame-src 'self' *.q2.com *.qualified.com *.doubleclick.net *.wistia.net *.gstatic.com *.google.com *.googletagmanager.com *.bugcrowd.com bugcrowd.com *.hubspotvideo.com *.marketo.com *.youtube.com *.pathfactory.com *.uberflip.com *.zuddl.com *.on24.com *.qualified.com; img-src 'self' *.q2.com data: *.hubspotusercontent-na1.net *.hsappstatic.net *.6sc.co *.cdntwrk.com *.cookielaw.org *.wistia.com *.hsforms.com *.linkedin.com *.hubspot.com *.hubspot.net *.bizible.com *.cloudinary.com *.clarity.ms *.bing.com *.googletagmanager.com *.placeholder.com *.marketo.com googleads.g.doubleclick.net *.doubleclick.net *.google.com *.doubleclick.net *.youtube.com *.hubspotusercontent40.net *.pathfactory.com *.bizibly.com *.gstatic.com *.zuddl.com *.imgix.net *.wistia.net *.qualified.com; manifest-src 'self'; media-src 'self' *.q2.com 7044196.fs1.hubspotusercontent-na1.net 7044196.fs2.hubspotusercontent-na1.net 7044196.fs1.hubspotusercontent-eu1.net 7044196.fs2.hubspotusercontent-eu1.net *.marketo.com blob: *.doubleclick.net *.youtube.com *.pathfactory.com; form-action 'self' *.marketo.com *.mktoweb.com *.zuddl.com *.callrail.com *.googleadservices.com *.qualified.com; frame-ancestors 'self' *.q2.com *.pathfactory.com *.lookbookhq.com; report-to https://343747560e392f7a31ae9a0247c09302.report-uri.com/r/d/csp/reportOnly
Date
Other
Fri, 07 Nov 2025 19:25:19 GMT
Edge-Cache-Tag
Other
CT-160753573422,P-7044196,CW-102379071093,CW-102379071095,CW-102379071098,CW-102379447684,CW-102379454293,CW-102380982173,CW-103490556982,CW-103490995268,CW-103490995281,CW-105463546169,CW-155446322271,CW-157895897748,CW-191986016413,E-102378065000,E-102378065008,E-102378985775,E-102378985778,E-102378985783,E-102379071107,E-102379071109,E-102379071111,E-102379258763,E-102379258765,E-102379258767,E-102379445420,E-102379445421,E-102379445422,E-102379447687,E-102379454315,E-102379454324,E-102380982182,E-102380982185,E-102951679585,E-103491024704,E-103640179623,E-109348757061,E-111437788316,E-111438452299,E-117953655627,E-156055520374,E-158735833755,E-163148657243,E-171797089320,E-182369584716,E-182369584719,PGS-ALL,SW-4,GC-103717217053,GC-125475360636,GC-125485556617,GC-167966791027,TS-102379454365
Link
Other
<https://cdn.cookielaw.org/scripttemplates/otSDKStub.js>; rel=preload; as=script,<https://fonts.googleapis.com>; rel=preconnect,<https://fonts.gstatic.com>; rel=preconnect,<https://fonts.googleapis.com/css2?family=Lexend:wght@300;400;500;600&display=swap>; rel=preload; as=style
Nel
Other
{"success_fraction":0.01,"report_to":"cf-nel","max_age":604800}
Report-To
Other
{"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=Yy1AFd9L6fO5rc0z4IG5oFXrUmMhfosXPSj1xvsP8T4IJDjqjWltLhBmH%2B%2BiuJCLDF0hbHZ7n842WvfHNyykRL7oeDTfZgiAGn6nXbXJPHWuyQ8PJbjkv9Pm7K8%3D"}],"group":"cf-nel","max_age":604800}
X-Hs-Cache-Config
Other
BrowserCache-5s-EdgeCache-0s
X-Hs-Cache-Control
Other
s-maxage=36000, max-age=0
X-Hs-Cf-Cache-Status
Other
HIT
X-Hs-Cfworker-Meta
Other
{"contentType":"SITE_PAGE","resolver":"PreRenderedContentResolver"}
X-Hs-Content-Id
Other
160753573422
X-Hs-Hub-Id
Other
7044196
X-Hs-Portal-Id
Other
7044196
X-Hs-Prerendered
Other
Fri, 07 Nov 2025 10:21:18 GMT

Recommendations

Enable compression (gzip/brotli) to improve performance

Analysis completed in 202ms