no-cache
keep-alive
gzip
default-src 'self' whatsapp:; connect-src https://*.tote.digital https://*.tote.rocks https://*.tote.live https://*.tote.co.uk https://api.addressy.com https://*.lot.to https://*.sportcaller.com https://*.mixpanel.com https://cdn.contentful.com https://preview.contentful.com https://sentry.io https://*.pusher.com wss://*.pusher.com https://*.intercom.io wss://*.intercom.io https://*.intercomcdn.com https://*.intercomusercontent.com https://www.facebook.com https://*.crazyegg.com https://*.maxmind.com https://stats.g.doubleclick.net https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com https://www.googleoptimize.com/ https://*.launchdarkly.com https://*.akamaized.net https://*.akamaihd.net https://*.attheraces.com https://adservice.google.com https://*.secure.footprint.net https://*.atgvision.com https://geoip-js.com https://*.appsflyer.com https://bat.bing.com https://*.oscato.com https://t.co https://google.com https://*.appsync-api.eu-west-2.amazonaws.com wss://*.appsync-realtime-api.eu-west-2.amazonaws.com https://*.tote.ie https://*.clarity.ms https://*.sports.tote.co.uk https://*.test.sports.tote.co.uk wss://*.sports.tote.co.uk wss://*.test.sports.tote.co.uk https://zz.connextra.com https://*.vercel.app/ https://*.hasura.app/ https://region1.google-analytics.com https://*.worldpay.com https://*.8count.tv/api/ https://www.google.com https://googleads.g.doubleclick.net/ https://pcast.phenixrts.com https://tote-dev4.abetting.co https://*.performgroup.com/ https://*.idscan.cloud/; form-action 'self' https://*.aircall.io https://js.intercomcdn.com https://intercom.help https://api-iam.intercom.io https://verify.monzo.com https://www.facebook.com https://*.oscato.com https://webapp.securetrading.net https://danskebank-3ds-vdm.wlp-acs.com https://www.clicksafe.lloydstsb.com https://*.arcot.com https://*.worldpay.com https://*.securesuite.co.uk https://*.cardinalcommerce.com; frame-ancestors 'self' https://*.idscan.cloud/; frame-src 'self' https://account.tote.digital https://account.test.tote.digital https://account.dev.tote.digital https://account.migration.tote.digital https://www.google.com https://account.staging.tote.live https://account.performance.tote.live https://account.live.tote.live https://account.tote.live https://account.staging.tote.co.uk https://account.performance.tote.co.uk https://account.live.tote.co.uk https://account.tote.co.uk https://thetote.atlassian.net https://tentofollow.test.tote.digital https://tentofollow-internal.tote.digital https://tentofollow.tote.live https://tentofollow.tote.co.uk https://flattentofollow.tote.co.uk https://minigame.tote.co.uk https://minigame.tote.digital https://colossus.stage.tote.co.uk https://colossus.tote.co.uk https://development.tote.digital https://test.tote.digital https://stage.tote.co.uk https://tote.co.uk https://test-branch.tote.digital https://intercom-sheets.com https://*.pariplaygames.com https://d21j22mhfwmuah.cloudfront.net https://player.vimeo.com https://www.youtube.com https://*.fls.doubleclick.net https://cdn.sportcaller.com https://*.adsrvr.org https://*.blueprintgaming.com https://*.rubyplay.com https://*.inspiredvirgo.com https://servedby.flashtalking.com/ https://wab-visualisation.performgroup.com/ https://www.facebook.com https://*.inseincvirtuals.com/ https://*.oscato.com https://*.prerelease-env.biz/ https://*.pragmaticplay.net/ https://wa.me/ https://*.userzoom.com https://app-pp.trunarrative.cloud https://app.trunarrative.cloud https://development-aws.tote.co.uk https://test-aws.tote.co.uk https://stage-aws.tote.co.uk https://*.pplivedealer.com https://*.lxy511.com https://*.pragmaticplaylive.net https://analytics.twitter.com https://c.bing.com https://www.googleoptimize.com https://*.vercel.app/ https://*.hasura.app/ https://pixel.mathtag.com https://*.tote.ie https://*.worldpay.com https://*.8count.tv/api/ https://lb.1x2nwh.com https://1x2-cloud-1.com https://www.1x2gamingcdn.com https://www.1x2-nwh-int-staging.com https://static-live.hacksawgaming.com https://static-stg.hacksawgaming.com https://pcast.phenixrts.com https://tote-dev4.abetting.co https://*.idscan.cloud/; img-src 'self' blob: data: https://icard.gbiracing.com https://*.tote.digital https://*.tote.rocks https://*.tote.live https://*.tote.co.uk https://*.tote.ie https://images.ctfassets.net https://images.racingpost.com https://*.googletagmanager.com https://static.intercomassets.com https://*.intercomcdn.com https://*.gstatic.com https://*.aircall.io https://*.micpn.com https://*.intercom.io https://*.intercom-attachments.com https://uploads.intercomusercontent.com https://lotto.nyc3.cdn.digitaloceanspaces.com https://www.facebook.com https://connect.facebook.net https://t.myvisualiq.net https://bat.bing.com https://tapestry.tapad.com https://t.co https://*.doubleclick.net https://tags.bluekai.com https://dpm.demdex.net https://loadus.exelator.com https://idsync.rlcdn.com https://www.google.com https://www.google.co.uk https://www.google.com.ua https://www.google.ie https://insight.adsrvr.org https://*.crazyegg.com https://*.google-analytics.com https://cx.atdmt.com https://servedby.flashtalking.com https://cdn.sportcaller.com https://*.oscato.com https://googleads.g.doubleclick.net https://*.userzoom.com https://*.clarity.ms https://*.vercel.app/ https://*.hasura.app/ https://sync.mathtag.com https://secure.adnxs.com https://segment.prod.bidr.io https://secure.adnxs.com https://match.prod.bidr.io https://zz.connextra.com/ https://cnv.event.prod.bidr.io/log/cnv https://pixel.mathtag.com https://*.worldpay.com https://*.8count.tv/api/ https://analytics.twitter.com https://pcast.phenixrts.com https://tote-dev4.abetting.co https://*.idscan.cloud/; manifest-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://*.pusher.com https://*.gstatic.com https://www.googletagmanager.com https://*.intercom.io https://js.intercomcdn.com https://*.google.com https://*.mxpnl.com https://thetote.atlassian.net https://*.micpn.com https://connect.facebook.net https://static.ads-twitter.com https://bat.bing.com https://*.myvisualiq.net https://www.googleadservices.com https://analytics.twitter.com https://*.crazyegg.com https://js.adsrvr.org https://*.google-analytics.com https://*.googletagmanager.com https://s3.amazonaws.com/trk.cetrk.com/7/t.js https://*.maxmind.com https://websdk.appsflyer.com https://*.userzoom.com https://*.oscato.com https://*.clarity.ms https://zz.connextra.com https://www.youtube.com/ https://*.vercel.app/ https://*.hasura.app/ https://www.googleoptimize.com/ https://pixel.mathtag.com/ https://*.worldpay.com/ https://*.8count.tv/api/ https://cdn.seondf.com/js/v5/agent.js https://*.performgroup.com/; font-src 'self' data: https://js.intercomcdn.com https://*.gstatic.com https://fonts.intercomcdn.com https://cdn.tote.co.uk; style-src 'self' 'unsafe-inline' https://*.google.com https://*.googleapis.com https://*.oscato.com https://*.tote.digital https://*.tote.rocks https://*.tote.live https://*.tote.ie https://*.tote.co.uk https://*.userzoom.com https://*.worldpay.com; media-src 'self' https://js.intercomcdn.com https://customer-n3fizij3iayvp17p.cloudflarestream.com https://*.akamaized.net https://*.akamaihd.net https://*.attheraces.com https://*.secure.footprint.net https://*.atgvision.com https://wab-visualisation.performgroup.com/ blob: https://betsmart-cms.vercel.app/api/get-jwt https://betsmart-app.hasura.app/api/rest/video https://betsmart-cms-git-staging-8count.vercel.app/api/get-jwt https://betsmart-app-stg.hasura.app/api/rest/video https://videodelivery.net/ https://*.8count.tv/api/ https://pcast.phenixrts.com; child-src https://share.intercom.io https://intercom-sheets.com https://www.intercom-reporting.com https://www.youtube.com https://player.vimeo.com https://fast.wistia.net https://wab-visualisation.performgroup.com/ https://*.attheraces.com https://*.oscato.com blob: https://betsmart-cms.vercel.app/api/get-jwt https://betsmart-app.hasura.app/api/rest/video https://betsmart-cms-git-staging-8count.vercel.app/api/get-jwt https://betsmart-app-stg.hasura.app/api/rest/video https://*.worldpay.com https://*.8count.tv/api/ https://pcast.phenixrts.com; worker-src blob:; upgrade-insecure-requests; report-uri https://thetote.report-uri.com/r/d/csp/reportOnly
text/html
Sat, 13 Jan 2024 12:58:53 GMT
W/"9ac55f5826701a91533cda2e81efa7fb"
geolocation 'self';
Fri, 12 Jan 2024 11:02:23 GMT
{report_to: 'default', max_age: 31536000, include_subdomains: true}
same-origin
{group: 'default', max_age: 31536000, endpoints: [{ url: 'https://thetote.report-uri.com/a/d/g' }], include_subdomains: true}
CloudFront
max-age=63072000; includeSubDomains; preload
1.1 f14d816589c938c13b4401641d90dcd2.cloudfront.net (CloudFront)
UGvtvGfBekW6zMYNowdmQhR0SXYA0sIurxWj6OvpUmKPXmnoI-tCCg==
DUB2-C1
Hit from cloudfront
nosniff
deny
1; mode=block; report=https://thetote.report-uri.com/r/d/xss/enforce
|