Blog/Headers

HTTP Security Headers: The Complete Guide + Free Scanner

Six headers. Dozens of attacks prevented. Here's what each one does, why it matters, and the exact syntax to add it to your server today.

May 12, 20268 min read

Why security headers matter

Security headers are the simplest and cheapest security improvements you can make to any website. Unlike application-level security (fixing code vulnerabilities, patching dependencies), headers are usually set in a single config file and take effect immediately — no deployment, no code changes, no testing cycles.

Despite this, over 60% of websites are missing at least one critical security header. Common reasons: developers don't know about them, default server configurations don't include them, and there's no automated testing catching their absence.

The 6 essential headers

Critical

Strict-Transport-Security (HSTS)

Tells browsers to only connect to your site over HTTPS — never HTTP. Prevents protocol downgrade attacks and cookie hijacking.

Strict-Transport-Security: max-age=31536000; includeSubDomains; preload

Risk without it: Without HSTS, an attacker on the same network can intercept an initial HTTP request and redirect it to a fake HTTP version of your site.

Tip: Start with max-age=86400 (1 day), verify everything works, then increase to 31536000 (1 year). Add preload only after confirming all subdomains support HTTPS.

Critical

Content-Security-Policy (CSP)

Specifies which sources the browser is allowed to load scripts, styles, images, and other resources from. The single most powerful header against XSS attacks.

Content-Security-Policy: default-src 'self'; script-src 'self' https://cdn.example.com; style-src 'self' 'unsafe-inline'

Risk without it: Without CSP, injected scripts (from XSS vulnerabilities or third-party compromises) run with full privileges and can steal data, manipulate UI, or exfiltrate credentials.

Tip: Start in report-only mode (Content-Security-Policy-Report-Only) to identify violations without breaking functionality, then gradually tighten the policy.

High

X-Frame-Options

Controls whether your page can be embedded in a <frame>, <iframe>, or <object>. Prevents clickjacking attacks where attackers overlay your site invisibly.

X-Frame-Options: DENY

Risk without it: Without this header, attackers can embed your site in a transparent iframe over a malicious page, tricking users into clicking on your UI elements unknowingly.

Tip: Use DENY unless you need to embed your own site in an iframe (use SAMEORIGIN in that case). CSP's frame-ancestors directive is the modern equivalent and overrides X-Frame-Options.

Medium

X-Content-Type-Options

Prevents MIME type sniffing — stops browsers from interpreting files as a different MIME type than declared. One line, no downsides.

X-Content-Type-Options: nosniff

Risk without it: Without this header, a browser may execute a text file as JavaScript if it looks like script, enabling XSS via uploaded file attacks.

Tip: This is a one-liner with no configuration needed. Every site should set it.

Medium

Referrer-Policy

Controls how much referrer information is sent when users navigate away from your site. Protects user privacy and prevents leaking sensitive URLs.

Referrer-Policy: strict-origin-when-cross-origin

Risk without it: Without a referrer policy, your full URL (including query parameters with user data, session IDs, etc.) may be sent to third-party sites via the Referer header.

Tip: strict-origin-when-cross-origin is a sensible default for most sites. It sends the origin for cross-origin requests and the full URL for same-origin.

Low-Medium

Permissions-Policy

Controls which browser features and APIs (camera, microphone, geolocation, payment, etc.) your page and any embedded iframes are allowed to use.

Permissions-Policy: camera=(), microphone=(), geolocation=(self)

Risk without it: Without this header, any iframe you embed could request camera or microphone access on your behalf. Malicious third-party scripts could also silently request sensitive permissions.

Tip: Deny all features you don't use. This follows the principle of least privilege and prevents unexpected API access from third-party embeds.

How to add headers on any platform

Nginx

add_header Strict-Transport-Security "max-age=31536000" always;

Apache (.htaccess)

Header always set Strict-Transport-Security "max-age=31536000"

Netlify (_headers)

/* Strict-Transport-Security: max-age=31536000

Vercel (vercel.json)

{"headers":[{"source":"/(.*)", "headers":[{"key":"Strict-Transport-Security","value":"max-age=31536000"}]}]}

How to check your headers

Flux8Shield scans any public URL and checks all 10+ security headers instantly — showing which are present, which are missing, and what misconfiguration risks exist. No signup, no installation, 100% passive scanning.

Check your security headers free

40+ checks. Instant results. No signup. Passive only.

Free Security Scan →

Frequently asked questions

What are HTTP security headers?

HTTP security headers are response headers sent by your web server that instruct browsers how to behave when handling your site's content. They protect against a wide range of attacks including XSS, clickjacking, protocol downgrade attacks, and information disclosure.

Do security headers affect SEO?

Indirectly, yes. HTTPS (enforced by HSTS) is a Google ranking factor. Security headers also signal trustworthiness to users, reducing bounce rates. Google explicitly checks for HTTPS as part of its Page Experience signal.

How do I add security headers to my website?

The method depends on your server or platform. Apache uses .htaccess, Nginx uses server block config, Netlify uses a _headers file or netlify.toml, Vercel uses vercel.json headers config, and Cloudflare can inject them at the edge without touching your server.

What is the most important security header?

For most sites: HSTS (prevents protocol downgrade attacks), followed by Content-Security-Policy (prevents XSS), and X-Frame-Options (prevents clickjacking). Together these three address the highest-impact browser-level attacks.

Can I check my security headers for free?

Yes. Flux8Shield scans any public URL and checks 10+ security headers instantly, with no signup required. It shows which headers are missing, which are misconfigured, and what the risk level is for each.