Open
Cached
·
just now
18
Headers
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=31536000
Content-Security-Policy
Good
default-src; script-src; style-src; +7 more
default-src 'self' p11.techlab-cdn.com;script-src 'self' 'unsafe-inline' *.cdw.com *.cdwg.com *.richrelevance.com *.qualtrics.com *.optimizely.com *.needle.com *.demandbase.com *.appspot.com *.facebook.net *.googleadservices.com *.doubleclick.net *.google-analytics.com *.bing.com *.googleapis.com *.akamaihd.net *.google.com *.twitter.com *.demdex.net *.d41.co *.cxense.com pactsafe.io *.webcollage.net *.googletagmanager.com *.googlesyndication.com *.googletagservices.com *.ytimg.com *.youtube.com *.easy2.com *.go-mpulse.net *.linkedin.com *.cdnwidget.com *.rlcdn.com *.cloudfront.net *.bluecore.com p.adsymptotic.com *.dotomi.com blob: *.flixsyndication.net data.g2.com *.g2crowd.com *.adobe.com *.omtrdc.net *.spexlive.net *.gstatic.com *.turnto.com *.licdn.com *.hs-scripts.com *.ispot.tv *.hsleadflows.net *.hs-banner.com *.hsforms.net *.hubapi.com *.syndigo.com *.syndigo.cloud *.hsforms.com *.hubspot-forms-static-embed.s3.amazonaws.com *.hubspot.com *.tiqcdn.com *.tealiumiq.com *.hs-analytics.net js.usemessages.com *.hscollectedforms.net *.redditstatic.com *.reddit.com *.adsrvr.org *.scene7.com *.vidyard.com *.vimeo.com *.hp.com *.etilize.com *.1worldsync.com *.quantserve.com *.quantcount.com *.spexaccess.net *.onetrust.com *.oribi.io *.cookielaw.org *.criteo.com *.criteo.net *.botframework.com *.administrateweblink.com *.stripe.com *.pactsafe.io *.peerspot.com *.sketchfab.com *.quantummetric.com *.fiservapps.com *.quora.com sierra.chat *.algorecs.com *.officeperceptioninstinct.com *.oktapreview.com *.okta.com *.adobedtm.com *.mktoresp.com *.mktoapi.com *.mktoweb.com *.mktoedge.com *.adobedc.net *.marketo.net *.adoberesources.net p11.techlab-cdn.com;style-src 'self' 'unsafe-inline' *.cdw.com *.cdwg.com *.needle.com *.googleapis.com *.webcollage.net *.easy2.com *.amazonaws.com *.cloudfront.net blob: *.typekit.net *.adobe.com *.omtrdc.net *.spexlive.net *.turnto.com *.syndigo.com *.syndigo.cloud *.scene7.com *.etilize.com *.1worldsync.com *.spexaccess.net *.administrateweblink.com *.stripe.com *.sketchfab.com *.quantummetric.com sierra.chat *.adobedtm.com;img-src 'self' *.cdw.com *.cdwg.com *.qualtrics.com *.optimizely.com *.needle.com *.googleadservices.com *.doubleclick.net *.google-analytics.com *.bing.com *.akamaihd.net *.google.com *.demdex.net *.cxense.com *.webcollage.net *.googletagmanager.com *.googletagservices.com *.ytimg.com *.youtube.com *.easy2.com *.amazonaws.com *.linkedin.com *.company-target.com *.facebook.com *.cdnwidget.com *.rlcdn.com *.cloudfront.net *.adobecqms.net *.everesttech.net *.bluecore.com *.prod.bidr.io cdn.optimizely.com p.adsymptotic.com data: *.dotomi.com *.flixsyndication.net *.adobe.com *.omtrdc.net *.spexlive.net *.windows.net *.turnto.com *.edgecastcdn.net *.licdn.com *.ispot.tv *.syndigo.com *.syndigo.cloud *.hsforms.com *.hubspot.com *.tiqcdn.com *.tealiumiq.com *.redditstatic.com *.reddit.com *.adsrvr.org *.scene7.com *.vidyard.com *.vimeocdn.com *.etilize.com *.1worldsync.com *.quantserve.com *.quantcount.com *.spexaccess.net *.oribi.io *.cookielaw.org *.criteo.com *.criteo.net *.pactsafe.io *.administratehq.com *.peerspot.com *.sketchfab.com *.quora.com sierra.chat *.officeperceptioninstinct.com *.oktapreview.com *.okta.com *.hubspotusercontent-na1.net *.adobedtm.com *.mktoedge.com;frame-src 'self' *.cdw.com *.cdwg.com *.qualtrics.com *.needle.com *.doubleclick.net *.google.com *.twitter.com *.demdex.net *.cxense.com *.webcollage.net *.googletagmanager.com *.googletagservices.com *.youtube.com *.easy2.com *.facebook.com *.rlcdn.com *.cloudfront.net *.cdwemail.com www.emjcd.com *.dotomi.com *.kingston.com *.flixsyndication.net *.adobe.com *.spexlive.net *.exct.net *.syndigo.com *.syndigo.cloud *.hsforms.com *.adsrvr.org *.scene7.com *.vidyard.com *.vimeo.com *.hp.com chromeos-selector-cdw-prod.web.app *.etilize.com *.1worldsync.com *.spexaccess.net *.onetrust.com *.criteo.com *.criteo.net *.se.com *.administrateweblink.com *.stripe.com *.sketchfab.com *.quantummetric.com *.fiservapps.com *.microsoft.com *.mktoweb.com *.adobedc.net;font-src * data:;connect-src 'self' *.cdw.com *.cdwg.com *.richrelevance.com *.qualtrics.com *.optimizely.com *.needle.com *.demandbase.com *.appspot.com *.googleadservices.com *.doubleclick.net *.google-analytics.com *.bing.com *.googleapis.com *.akamaihd.net *.google.com *.demdex.net *.d41.co *.cxense.com *.webcollage.net *.googletagmanager.com *.googletagservices.com *.go-mpulse.net *.linkedin.com *.company-target.com *.facebook.com *.cdnwidget.com *.cloudfront.net *.bluecore.com p.adsymptotic.com *.cdnbasket.net *.akstat.io data.g2.com *.g2crowd.com *.adobe.com *.omtrdc.net *.spexlive.net *.turnto.com *.ispot.tv *.hubapi.com *.syndigo.com *.syndigo.cloud *.hsforms.com *.hubspot-forms-static-embed.s3.amazonaws.com *.hubspot.com *.tiqcdn.com *.tealiumiq.com *.scene7.com *.addressy.com *.etilize.com *.1worldsync.com *.quantserve.com *.spexaccess.net *.onetrust.com *.oribi.io *.cookielaw.org *.criteo.com *.criteo.net *.botframework.com wss://*.botframework.com *.administrateweblink.com *.pactsafe.io *.administratehq.com *.sketchfab.com *.quantummetric.com sierra.chat *.algorecs.com *.adobedtm.com *.mktoresp.com *.mktoapi.com *.mktoweb.com *.mktoedge.com *.adobedc.net *.marketo.net p11.techlab-cdn.com;object-src 'self' *.cdw.com *.scene7.com;media-src 'self' *.cdw.com *.webcollage.net *.youtube.com blob: *.flixsyndication.net *.spexlive.net *.syndigo.com *.syndigo.cloud *.tiqcdn.com *.scene7.com *.etilize.com *.1worldsync.com *.spexaccess.net *.sketchfab.com;worker-src 'self' *.needle.com *.cloudfront.net blob: *.quantummetric.com;
X-Frame-Options
Good
SAMEORIGIN
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Strengthen CSP by removing 'unsafe-eval'
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
Performance Headers
2 headers
Connection
Performance
Transfer-Encoding
Transfer-Encoding
Performance
chunked
Caching Headers
2 headers
Cache-Control
Caching
no-store, no-cache
Pragma
Caching
no-cache
Content Headers
1 headers
Content-Type
Content
text/html; charset=utf-8
Server Headers
0 headers
No server headers found
CORS Headers
0 headers
No CORS headers found
Cookies Headers
1 headers
Set-Cookie
Cookies
bm_sz=A1D178D5930C3571414297DD199AE489~YAAQkGvcFwJytk+bAQAABeAecR4xeBF1x6pMEwFYjpS4ZUeNfr+/2CPhEh0dse98qmv0OGqoKB4o8bdkcKSmI8CwFocQiG6z5cBQtaIxtOmpcOIr3DkSdhBY+kUe8xdz/zCNZv4jYJ2o561/sBcGveOlXQrnoDUNDL8cS3LVDfx3SgUtLA1cKPChOXQjnY4llmTCHbFBGZnlEZk+zHzz/c64SyjQN2M9/PVOi6WhK/3jIfTFuCHrwtvYggrS2jOyFJsyizE8A5EiBxy9Wnz8n/ag+ISLafA3wzjUeJ69PMcAKOIoHoxvonIyAXKw4nDpfcrKlsS9eskRwgFjNnuaDJ++Y/MBR1BsNw==~3355445~3228208; Domain=.cdwg.com; Path=/; Expires=Wed, 31 Dec 2025 01:16:47 GMT; Max-Age=14400; SameSite=None; Secure
Other Headers
7 headers
Date
Other
Tue, 30 Dec 2025 21:16:47 GMT
P3p
Other
CP="CAO DSP DEVa TAIa OUR BUS UNI FIN COM NAV INT STA"
Server-Timing
Other
ak_p; desc="1767129407392_400321424_1003832155_5724_12508_1_4_-";dur=1
X-Akam-Sw-Version
Other
0.5.0
X-Akamai-Transformed
Other
9l 28831 0 pmb=mRUM,2
X-Cdw-Device
Other
desktop
X-Cdw-Member
Other
101
Recommendations
Enable compression (gzip/brotli) to improve performance