HTTP Security Headers Explained

Security headers are HTTP response headers that instruct browsers to enforce security policies. They're one of the easiest and most effective ways to protect your website from common attacks.

Essential Headers

Strict-Transport-Security (HSTS)

Forces browsers to only connect via HTTPS, preventing protocol downgrade attacks and cookie hijacking.

Strict-Transport-Security: max-age=31536000; includeSubDomains; preload

Content-Security-Policy (CSP)

Controls which resources the browser can load. The most powerful defense against XSS attacks.

Content-Security-Policy: default-src 'self'; script-src 'self' 'unsafe-inline'

X-Frame-Options

Prevents your page from being loaded in iframes, blocking clickjacking attacks.

X-Frame-Options: DENY

X-Content-Type-Options

Prevents browsers from MIME-sniffing the content type, reducing drive-by download attacks.

X-Content-Type-Options: nosniff

Referrer-Policy

Controls how much referrer information is shared when navigating away from your site.

Referrer-Policy: strict-origin-when-cross-origin

Advanced Headers

Permissions-Policy

Controls which browser features (camera, microphone, geolocation) your site can access.

Permissions-Policy: camera=(), microphone=(), geolocation=()

Cross-Origin Headers (COOP/CORP/COEP)

A family of headers that provide cross-origin isolation, enabling features like SharedArrayBuffer and protecting against Spectre-like attacks.

Implementation Tips