tillamook.com | Analytics by SecurityHeaders

HTTP Headers report for tillamook.com

Header Name Header Data
HTTP status code 200
Cache-Control private, no-cache, no-store, max-age=0, must-revalidate
X-Content-Type-Options nosniff
X-Dns-Prefetch-Control on
X-Matched-Path /[[...slug]]
X-Xss-Protection 1; mode=block
Link </_next/static/css/bdbe56d0684d3227.css?dpl=dpl_GhgYbcXrd7WUFrcGD4qLxgjbs39H>; rel=preload; as="style", </_next/static/css/d762c0275294fdea.css?dpl=dpl_GhgYbcXrd7WUFrcGD4qLxgjbs39H>; rel=preload; as="style", </_next/static/css/d99685703f213429.css?dpl=dpl_GhgYbcXrd7WUFrcGD4qLxgjbs39H>; rel=preload; as="style", </_next/static/css/e69715b3b05cd7e6.css?dpl=dpl_GhgYbcXrd7WUFrcGD4qLxgjbs39H>; rel=preload; as="style", </_next/static/css/0efce02d976a2a68.css?dpl=dpl_GhgYbcXrd7WUFrcGD4qLxgjbs39H>; rel=preload; as="style", </_next/static/css/a5457909ec540e6d.css?dpl=dpl_GhgYbcXrd7WUFrcGD4qLxgjbs39H>; rel=preload; as="style", </_next/static/css/c2f6d46505adc5f2.css?dpl=dpl_GhgYbcXrd7WUFrcGD4qLxgjbs39H>; rel=preload; as="style", </_next/static/css/59099709e735d07e.css?dpl=dpl_GhgYbcXrd7WUFrcGD4qLxgjbs39H>; rel=preload; as="style", </_next/static/css/6514965595327c0c.css?dpl=dpl_GhgYbcXrd7WUFrcGD4qLxgjbs39H>; rel=preload; as="style", </_next/static/css/47604edffe1b7f77.css?dpl=dpl_GhgYbcXrd7WUFrcGD4qLxgjbs39H>; rel=preload; as="style", </_next/static/css/8eb9359f32c8c449.css?dpl=dpl_GhgYbcXrd7WUFrcGD4qLxgjbs39H>; rel=preload; as="style", </_next/static/css/6cc36118cb9eb729.css?dpl=dpl_GhgYbcXrd7WUFrcGD4qLxgjbs39H>; rel=preload; as="style", </_next/static/css/9d0c6a6f41c3dbb6.css?dpl=dpl_GhgYbcXrd7WUFrcGD4qLxgjbs39H>; rel=preload; as="style", </_next/static/css/92fe1643c2b2eea5.css?dpl=dpl_GhgYbcXrd7WUFrcGD4qLxgjbs39H>; rel=preload; as="style", </_next/static/css/add47d022b84019f.css?dpl=dpl_GhgYbcXrd7WUFrcGD4qLxgjbs39H>; rel=preload; as="style", </_next/static/css/18433ccd8c95e522.css?dpl=dpl_GhgYbcXrd7WUFrcGD4qLxgjbs39H>; rel=preload; as="style", </_next/static/css/eb375b4512696b53.css?dpl=dpl_GhgYbcXrd7WUFrcGD4qLxgjbs39H>; rel=preload; as="style", </_next/static/css/f474593bb09b6a6d.css?dpl=dpl_GhgYbcXrd7WUFrcGD4qLxgjbs39H>; rel=preload; as="style", </_next/static/css/693da7f3e962c1cf.css?dpl=dpl_GhgYbcXrd7WUFrcGD4qLxgjbs39H>; rel=preload; as="style", </_next/static/css/f5e3bcfd7ccedffd.css?dpl=dpl_GhgYbcXrd7WUFrcGD4qLxgjbs39H>; rel=preload; as="style", </_next/static/css/d36626575a455660.css?dpl=dpl_GhgYbcXrd7WUFrcGD4qLxgjbs39H>; rel=preload; as="style", </_next/static/css/3efdde5c29258eda.css?dpl=dpl_GhgYbcXrd7WUFrcGD4qLxgjbs39H>; rel=preload; as="style"
Referrer-Policy no-referrer, strict-origin-when-cross-origin
Server Vercel
X-Vercel-Cache MISS
Age 0
Date Sun, 20 Apr 2025 07:50:50 GMT
Report-To {"group":"default","max_age":10886400,"endpoints":[{"url":"https://16x3230g.uriports.com/reports"}],"include_subdomains":true}
Strict-Transport-Security max-age=63072000; includeSubDomains; preload
X-Vercel-Id fra1::pdx1::6cbzf-1745135450544-a4873dffb0c9
Content-Security-Policy-Report-Only default-src 'self' *.tillamook.com tillamook.com stackpath.bootstrapcdn.com; img-src 'self' data: *.ctfassets.net ctfassets.net *.cookielaw.org cookielaw.org www.google.com/ads/ www.google-analytics.com/ www.facebook.com/ c.lytics.io/c/b5c7317d218cb2a0ef160219694b5a9e www.googletagmanager.com; media-src 'self' *.ctfassets.net ctfassets.net; script-src 'self' 'unsafe-inline' 'unsafe-eval' blob: destinilocators.com https://connect.facebook.net/ *.hotjar.com hotjar.com *.klaviyo.com klaviyo.com *.cookielaw.org cookielaw.org www.google-analytics.com/ www.googletagmanager.com/ www.google.com/recaptcha/ www.gstatic.com/recaptcha/ www.clarity.ms givebutter.com/ destinilocators.com/ www.googleoptimize.com/ cdnjs.cloudflare.com/polyfill/v3/polyfill.min.js cdnjs.cloudflare.com/ajax/libs/iframe-resizer/2.8.10/iframeResizer.min.js cdnjs.cloudflare.com/ajax/libs/easyXDM/2.4.20/easyXDM.min.js c.lytics.io/ va.vercel-scripts.com/v1/speed-insights/script.debug.js widget.intercom.io js.intercomcdn.com www.recaptcha.net analytics.tiktok.com/i18n/pixel/events.js; style-src 'self' 'unsafe-inline' *.typekit.net typekit.net api.tiles.mapbox.com www.exploretock.com stackpath.bootstrapcdn.com/font-awesome/4.7.0/css/font-awesome.min.css fonts.googleapis.com/css; style-src-elem 'self' 'unsafe-inline' *.typekit.net c.lytics.io stackpath.bootstrapcdn.com fonts.googleapis.com; font-src 'self' *.tillamook.com tillamook.com *.typekit.net typekit.net www.exploretock.com stackpath.bootstrapcdn.com fonts.gstatic.com; connect-src 'self' wss: *.tillamook.com tillamook.com *.tillamaps.com tillamaps.com *.hotjar.com hotjar.com *.klaviyo.com klaviyo.com *.doubleclick.net doubleclick.net *.ingest.sentry.io *.ingest.us.sentry.io *.ctfassets.net ctfassets.net *.mapbox.com mapbox.com *.algolianet.com *.algolia.net *.onetrust.com onetrust.com *.cookielaw.org cookielaw.org analytics.google.com api.addresszen.com *.clarity.ms/collect www.recaptcha.net preview.contentful.com/ www.google-analytics.com/ vitals.vercel-insights.com/ cdn.contentful.com/ analytics.google.com/ d2k6913brarspg.cloudfront.net/ www.facebook.com/tr/ analytics.tiktok.com/api/v2/pixel; frame-src 'self' https://vars.hotjar.com https://www.facebook.com/ https://www.google.com/ https://www.youtube.com https://www.youtube-nocookie.com https://destinilocators.com/ https://td.doubleclick.net/; frame-ancestors https://app.contentful.com; worker-src 'self' blob:; child-src 'self' blob:; report-uri https://16x3230g.uriports.com/reports/report; report-to default
Content-Type text/html; charset=utf-8
Permissions-Policy camera=(), microphone=()
Vary RSC, Next-Router-State-Tree, Next-Router-Prefetch, Next-Router-Segment-Prefetch

About the tool

By using SecurityHeaders.info, you can quickly identify missing or misconfigured headers and take steps to secure your website, improving both security and user confidence.

This tool is widely used by developers, security professionals, and organizations to ensure their websites adhere to best practices in web security.

We also have another analytic tool that is used for identifying popularity metrics, general information about the business, finding similar products and competitors, and much more.

Watch it now at TrustRadar