Official HubSpot domains required for CMS, forms, analytics, and other HubSpot features
script-src
Controls which scripts can be loaded and executed
style-src
Controls which stylesheets can be loaded
img-src
Controls which images can be loaded
connect-src
Controls which URLs can be loaded using script interfaces (fetch, XHR, WebSocket)
frame-src
Controls which URLs can be loaded in frames
child-src
Controls which URLs can be embedded as child browsing contexts
font-src
Controls which fonts can be loaded
Additional domains required when using HubSpot's EU data center
script-src
Controls which scripts can be loaded and executed
img-src
Controls which images can be loaded
connect-src
Controls which URLs can be loaded using script interfaces (fetch, XHR, WebSocket)
frame-src
Controls which URLs can be loaded in frames
Common domains for Google Analytics, Tag Manager, and Fonts
script-src
Controls which scripts can be loaded and executed
style-src
Controls which stylesheets can be loaded
img-src
Controls which images can be loaded
connect-src
Controls which URLs can be loaded using script interfaces (fetch, XHR, WebSocket)
frame-src
Controls which URLs can be loaded in frames
font-src
Controls which fonts can be loaded
Domains required for LinkedIn Insight Tag and other LinkedIn features
script-src
Controls which scripts can be loaded and executed
img-src
Controls which images can be loaded
connect-src
Controls which URLs can be loaded using script interfaces (fetch, XHR, WebSocket)
Domains required for Hotjar analytics and feedback tools
script-src
Controls which scripts can be loaded and executed
style-src
Controls which stylesheets can be loaded
img-src
Controls which images can be loaded
connect-src
Controls which URLs can be loaded using script interfaces (fetch, XHR, WebSocket)
frame-src
Controls which URLs can be loaded in frames
font-src
Controls which fonts can be loaded
Domains required for Unicorn Studio assets and features
img-src
Controls which images can be loaded