For DTM both Launch, you'll need to add `unsafe-inline` to the security policy (you can add the domains as in the OP to limit it to a subset of domains). The whole point of CSP is to block dynamic loading of scripts, which is sort of what tag managers do.at.js 1.X also uses eval(), so if you're usi...