HTTP Security Headers Explained
Security headers are HTTP response headers that instruct browsers to enforce security policies. They're one of the easiest and most effective ways to protect your website from common attacks.
Essential Headers
Strict-Transport-Security (HSTS)
Forces browsers to only connect via HTTPS, preventing protocol downgrade attacks and cookie hijacking.
Strict-Transport-Security: max-age=31536000; includeSubDomains; preloadContent-Security-Policy (CSP)
Controls which resources the browser can load. The most powerful defense against XSS attacks.
Content-Security-Policy: default-src 'self'; script-src 'self' 'unsafe-inline'X-Frame-Options
Prevents your page from being loaded in iframes, blocking clickjacking attacks.
X-Frame-Options: DENYX-Content-Type-Options
Prevents browsers from MIME-sniffing the content type, reducing drive-by download attacks.
X-Content-Type-Options: nosniffReferrer-Policy
Controls how much referrer information is shared when navigating away from your site.
Referrer-Policy: strict-origin-when-cross-originAdvanced Headers
Permissions-Policy
Controls which browser features (camera, microphone, geolocation) your site can access.
Permissions-Policy: camera=(), microphone=(), geolocation=()Cross-Origin Headers (COOP/CORP/COEP)
A family of headers that provide cross-origin isolation, enabling features like SharedArrayBuffer and protecting against Spectre-like attacks.
Implementation Tips
- Start with a report-only CSP to avoid breaking functionality
- Test thoroughly — overly strict policies can break your site
- Use tools like our Security Headers Analyzer to audit your headers
- Configure headers at the web server or CDN level for consistency