HTTP/2 301
content-type: text/html; charset=iso-8859-1
content-length: 278
location: https://blog.dropbox.com/2014/08/introducing-more-powerful-dropbox-pro
date: Sat, 01 Aug 2026 12:06:13 GMT
expires: Sat, 01 Aug 2026 12:06:13 GMT
server: Apache
x-dispatcher: dispatcher1uswest1-28644689
x-vhost: dropbox-prod.adobemsbasic.com
cache-control: max-age=0
x-cache: Miss from cloudfront
via: 1.1 89faf07e4e8786ed37541c47de012ab4.cloudfront.net (CloudFront)
x-amz-cf-pop: BOM78-P10
x-amz-cf-id: gv3H3GUzF6vovCAskXoLekCrtfhvaPgSl_nCsFiVQ3mk8KiFY_b1tA==
HTTP/2 301
content-type: text/html; charset=iso-8859-1
content-length: 235
location: https://www.dropbox.com/pro
date: Sat, 01 Aug 2026 12:06:13 GMT
expires: Sat, 01 Aug 2026 12:06:13 GMT
server: Apache
x-dispatcher: dispatcher2uswest1-28645028
x-vhost: dropbox-prod.adobemsbasic.com
cache-control: max-age=0
x-cache: Miss from cloudfront
via: 1.1 89faf07e4e8786ed37541c47de012ab4.cloudfront.net (CloudFront)
x-amz-cf-pop: BOM78-P10
x-amz-cf-id: VkztuNbtoVeR8uZ1ulWjRcTfJdF2X2PiNtk7mwfg09-8bpsF90UZYQ==
HTTP/2 301
content-type: text/html; charset=utf-8
content-security-policy: sandbox
cross-origin-opener-policy-report-only: same-origin; report-to=coop-coop
location: /overview/professionals
referrer-policy: strict-origin-when-cross-origin
reporting-endpoints: csp-metaserver-whitelist="https://www.dropbox.com/csp_log?policy_name=metaserver-whitelist", max_age=10886400, csp-metaserver-dynamic="https://www.dropbox.com/csp_log?policy_name=metaserver-dynamic", max_age=10886400, coop-coop="https://www.dropbox.com/csp_log?policy_name=coop", max_age=10886400, coop-dws2="https://www.dropbox.com/csp_log?policy_name=coop-dws2", max_age=10886400, coop-metaserver="https://www.dropbox.com/csp_log?policy_name=coop-metaserver", max_age=10886400
set-cookie: gvc=MTgxNjIzMDA2OTYxMjg3MzQ4MjMzNzIyNDI0Nzk4OTkzOTM1MDIw; expires=Thu, 31 Jul 2031 12:06:14 GMT; HttpOnly; Path=/; SameSite=None; Secure
set-cookie: t=tW29YDSi1yh5e-BMtGJw_UCz; Domain=dropbox.com; expires=Sun, 01 Aug 2027 12:06:14 GMT; HttpOnly; Path=/; SameSite=None; Secure
set-cookie: __Host-js_csrf=tW29YDSi1yh5e-BMtGJw_UCz; expires=Sun, 01 Aug 2027 12:06:14 GMT; Path=/; SameSite=None; Secure
set-cookie: __Host-ss=2AP8ckOBP8; expires=Sun, 01 Aug 2027 12:06:14 GMT; HttpOnly; Path=/; SameSite=Strict; Secure
set-cookie: locale=en; Domain=dropbox.com; expires=Thu, 31 Jul 2031 12:06:14 GMT; Path=/; SameSite=None; Secure
x-content-type-options: nosniff
x-frame-options: SAMEORIGIN
x-permitted-cross-domain-policies: none
x-xss-protection: 1; mode=block
date: Sat, 01 Aug 2026 12:06:14 GMT
server: envoy
strict-transport-security: max-age=31536000; includeSubDomains
strict-transport-security: max-age=31536000; includeSubDomains
content-length: 125
x-dropbox-trace-id: 3ed3f39c33794147bb2b4fd66a6de136
cache-control: no-cache, no-store
alt-svc: h3=":443"; ma=86400, h3-29=":443"; ma=86400
x-dropbox-response-origin: far_remote
x-dropbox-request-id: 3ed3f39c33794147bb2b4fd66a6de136
HTTP/2 200
content-security-policy: base-uri 'self'; child-src https://www.dropbox.com/static/serviceworker/ blob:; connect-src https://* ws://127.0.0.1:*/ws blob: wss://dsimports.dropbox.com/; default-src 'none'; font-src 'self' data: https://*; form-action 'self' https://www.dropbox.com/ https://dl-web.dropbox.com/ https://photos.dropbox.com/ https://paper.dropbox.com/ https://showcase.dropbox.com/ https://www.hellofax.com/ https://app.hellofax.com/ https://www.hellosign.com/ https://app.hellosign.com/ https://docsend.com/ https://www.docsend.com/ https://help.dropbox.com/ https://navi.dropbox.jp/ https://a.sprig.com/ https://selfguidedlearning.dropboxbusiness.com/ https://instructorledlearning.dropboxbusiness.com/ https://sales.dropboxbusiness.com/ https://accounts.google.com/ https://api.login.yahoo.com/ https://login.yahoo.com/ https://experience.dropbox.com/ https://pal-test.adyen.com https://2e83413d8036243b-Dropbox-pal-live.adyenpayments.com/ https://onedrive.live.com/picker https://*.sharepoint.com/; frame-ancestors 'self'; frame-src https://* dbapi-6: dbapi-7: dbapi-8: dropbox-client: itms-apps: itms-appss: blob:; img-src https://* data: blob:; media-src https://* blob:; object-src 'self' https://cfl.dropboxstatic.com/static/ https://www.dropboxstatic.com/static/ https://edge-live.dropboxstatic.com/static/; report-to csp-metaserver-whitelist; report-uri https://www.dropbox.com/csp_log?policy_name=metaserver-whitelist; script-src 'unsafe-eval' 'inline-speculation-rules' https://www.dropbox.com/static/api/ https://www.dropbox.com/pithos/ https://cfl.dropboxstatic.com/static/ https://www.dropboxstatic.com/static/ https://edge-live.dropboxstatic.com/static/ https://accounts.google.com/gsi/client https://reveal.clearbit.com/v1/companies/reveal https://www.paypal.com/sdk/js https://applepay.cdn-apple.com https://snippet.meticulous.ai/record/ https://edge.cofra.me/cf-static-97646a4fe3e6.js https://edge.cofra.me/cf-static-4d85f2a0ba2d.js 'nonce-bgh88duHM+Y3ldkWjZtgjrGkqEg='; style-src https://* 'unsafe-inline' 'unsafe-eval'; worker-src https://www.dropbox.com/static/serviceworker/ https://www.dropbox.com/encrypted_folder_download/service_worker.js https://www.dropbox.com/service_worker.js blob:
content-security-policy: report-to csp-metaserver-dynamic; report-uri https://www.dropbox.com/csp_log?policy_name=metaserver-dynamic; script-src 'unsafe-eval' 'strict-dynamic' 'nonce-bgh88duHM+Y3ldkWjZtgjrGkqEg=' 'nonce-5r1RiP2pftmU43RavzpIuf8SnmU='
content-type: text/html; charset=utf-8
cross-origin-opener-policy: same-origin-allow-popups
pragma: no-cache
referrer-policy: strict-origin-when-cross-origin
reporting-endpoints: coop-dws2="https://www.dropbox.com/csp_log?policy_name=coop-dws2", max_age=10886400, csp-metaserver-whitelist="https://www.dropbox.com/csp_log?policy_name=metaserver-whitelist", max_age=10886400, csp-metaserver-dynamic="https://www.dropbox.com/csp_log?policy_name=metaserver-dynamic", max_age=10886400
set-cookie: __Host-logged-out-session=ChCAsv4qNPLAi6wxNnImFddHELfCt9MGGi5BUkNIWlZmT19GX09oVzZLdE0wZk1UWXQ5VGR2ZXpwTEE2M0o5blh2a21kOWtB; Path=/; HttpOnly; Secure; SameSite=None
x-content-type-options: nosniff
x-frame-options: SAMEORIGIN
x-permitted-cross-domain-policies: none
x-xss-protection: 1; mode=block
date: Sat, 01 Aug 2026 12:06:15 GMT
strict-transport-security: max-age=31536000; includeSubDomains
server: envoy
cache-control: no-cache, no-store
alt-svc: h3=":443"; ma=86400, h3-29=":443"; ma=86400
content-encoding: gzip
vary: Accept-Encoding
x-dropbox-response-origin: far_remote
x-dropbox-request-id: 1848efc577f744c3b8fdac456a6de137
Dropbox for Professionals - Dropbox