h3=":443"; ma=86400
no-cache, no-store, must-revalidate, pre-check=0, post-check=0
keep-alive
gzip
block-all-mixed-content; default-src 'self'; base-uri 'self'; form-action 'self' flightbookings.airnewzealand.co.kr flightbookings.airnewzealand.kr flightbookings.airnewzealand.ca flightbookings.airnewzealand.cn flightbookings.airnewzealand.co.nz flightbookings.airnewzealand.co.uk flightbookings.airnewzealand.com.au flightbookings.airnewzealand.com.hk flightbookings.airnewzealand.com.sg flightbookings.airnewzealand.com.tw flightbookings.airnewzealand.com flightbookings.airnewzealand.de flightbookings.airnewzealand.eu flightbookings.airnewzealand.fr flightbookings.airnewzealand.hk flightbookings.airnewzealand.jp flightbookings.airnewzealand.pf flightbookings.airnewzealand.tw flightbookings.airnewzealand.com.cn flightbookings.grabaseat.co.nz flightbookings.airnewzealand.co.jp identity.airnewzealand.com au-connect.authsignal.com auth.identity.airnewzealand.com auth.identity.qual.airnewzealand.com auth.airnewzealand.co.nz auth.airnewzealand.eu; script-src 'self' p-airnz.com 'unsafe-inline' 'unsafe-eval' *.googleapis.com *.gstatic.com *.google.com *.ggpht.com *.googleusercontent.com flightbookings.airnewzealand.co.nz player.vimeo.com www.youtube.com s.ytimg.com s.wayin.com xd.wayin.com s.engagesciences.com display.engagesciences.com *.demdex.net www.google-analytics.com analytics.google.com tagmanager.google.com www.googletagmanager.com *.doubleclick.net www.googleadservices.com www.googletagservices.com www.google.com pagead2.googlesyndication.com cdn-assets-prod.s3.amazonaws.com *.optimizely.com optimizely-hrd.appspot.com optimizely.s3.amazonaws.com s.swiftypecdn.com upgrade.plusgrade.com nebula-cdn.kampyle.com screencapture.kampyle.com screencaptue-cdn.kampyle.com static.hotjar.com script.hotjar.com yourir.info auth.airnewzealand.co.nz auth.airnewzealand.eu ssl.google-analytics.com cdnjs.cloudflare.com res.levexis.com https://widget.timatic.iata.org/scripts/iata-timatic-widget-live.js; style-src 'unsafe-inline' p-airnz.com fonts.googleapis.com tagmanager.google.com s.swiftypecdn.com upgrade-cdn-prd.plusgrade.com static.hotjar.com script.hotjar.com yourir.info 'self'; img-src https: data: static.hotjar.com script.hotjar.com; font-src p-airnz.com fonts.googleapis.com fonts.gstatic.com dhm5hy2vn8l0l.cloudfront.net script.hotjar.com 'self' data:; media-src 'self' video.cdnvue.com ; frame-src 'self' *.google.com auth.identity.airnewzealand.com nz.fltmaps.com player.youku.com v.qq.com player.vimeo.com www.youtube.com airnz.wufoo.com xd.wayin.com display.engagesciences.com *.demdex.net *.doubleclick.net www.googletagmanager.com *.cdn-pci.optimizely.com nebula-cdn.kampyle.com vars.hotjar.com sec.windcave.com uat.windcave.com forms.cd.airnewzealand.co.nz www.airnewzealand.co.nz/airpoints-account/payments/scripts/done.html; connect-src 'self' api.airnz.io api.airnz.ai *.googleapis.com *.google.com *.gstatic.com auth.airnewzealand.co.nz auth.airnewzealand.eu identity.airnewzealand.com *.demdex.net *.tt.omtrdc.net www.google-analytics.com region1.google-analytics.com region1.analytics.google.com analytics.google.com stats.g.doubleclick.net adservice.google.com pagead2.googlesyndication.com *.optimizely.com s.swiftypecdn.com search-api.swiftype.com *.kampyle.com https://*.hotjar.com https://*.hotjar.io wss://*.hotjar.com https://*.sentry.io yourir.info ssl.google-analytics.com https://widget.timatic.iata.org/api/ sec.windcave.com uat.windcave.com; object-src 'none'; frame-ancestors 'self'; report-uri /csp-report
text/html; charset=UTF-8
Wed, 10 Jan 2024 05:47:37 GMT
Tue, 09 Jan 2024 04:41:04 GMT
geolocation=(self "https://p-airnz.com"), camera=(), fullscreen=(self "https://www.youtube.com"), accelerometer=(), gyroscope=(), magnetometer=(), microphone=(), midi=(), payment=(), screen-wake-lock=(), sync-xhr=(*), usb=(), web-share=(), clipboard-read=(), clipboard-write=()
strict-origin
nginx
max-age=31536000; includeSubDomains;
Accept-Encoding
1.1 dfd84a17eaa88d79994b6524cab4931e.cloudfront.net (CloudFront)
Fs9RdUDXlZpOvfCzE8sPp9SjAxVkMADuBnDQDgUDd_sVGZxZL9HceQ==
DUB56-P1
Miss from cloudfront
nosniff
SAMEORIGIN
1; mode=block
|