[Atomic Glue](atomicglue.co)
SECURITY
Home › Glossary › Security· 362 ·

Security Headers

si-kyoor-i-tee hed-ersnoun phrase
Filed underSecurityWeb Development
In brief · quick answer

Security headers are HTTP response headers that instruct browsers to enable security protections. They prevent common attacks including XSS, clickjacking, MIME sniffing, and protocol downgrades.

§ 1 Definition

Security headers are HTTP response headers that a web server sends to a browser to enable security features and restrictions. They form a critical layer of defense-in-depth for any web application. Key security headers include: Content-Security-Policy (controls resource loading), Strict-Transport-Security (forces HTTPS), X-Content-Type-Options (prevents MIME sniffing), X-Frame-Options (prevents clickjacking), Referrer-Policy (controls referrer information), and Permissions-Policy (controls browser features). Tools like securityheaders.com and Mozilla Observatory scan and grade a site's security header implementation.

§ 2 Essential Security Headers

Content-Security-Policy (CSP): Controls which resources can be loaded. Most powerful security header. Strict-Transport-Security (HSTS): Forces HTTPS connections. X-Content-Type-Options: nosniff: Prevents MIME type sniffing attacks. X-Frame-Options: DENY or SAMEORIGIN: Prevents clickjacking by controlling iframe embedding. Referrer-Policy: Controls how much referrer information is sent with requests. Permissions-Policy (formerly Feature-Policy): Controls which browser APIs and features the page can use (camera, microphone, geolocation).

§ 3 Security Header Scoring

securityheaders.com provides an A-to-F rating for a site's security headers. An A+ rating requires: Strict-Transport-Security (with preload), Content-Security-Policy (or proper X-Frame-Options), X-Content-Type-Options, and Referrer-Policy. Mozilla Observatory provides a similar grading system with more granular scoring. Achieving a high score on these tools is a good indicator of baseline web security, but headers must be configured correctly for your specific application, not just for the score.

§ 4 Common Misconfigurations

Setting CSP with 'unsafe-inline' effectively disables XSS protection. Setting HSTS with a short max-age provides minimal protection. Omitting the 'includeSubDomains' flag on HSTS leaves subdomains exposed to downgrade. Setting X-Frame-Options when CSP's frame-ancestors already controls framing (use one or the other). Missing the Secure flag on cookies. Setting Permissions-Policy too restrictively (blocking legitimate features) or not at all.

§ 5 Note

Use securityheaders.com and Mozilla Observatory to test your site's headers. Aim for grade A/A+ on both. Test headers after every deployment to catch regressions.

§ 6 Common questions

Q. What is the single most important security header?
A. Content-Security-Policy (CSP) with a strict, nonce-based policy is the most powerful single header, as it prevents XSS and data injection attacks. HSTS is a close second for ensuring encrypted connections.
Q. Can security headers break my website?
A. Yes. CSP can block legitimate resources. X-Frame-Options can break valid iframe embeds. Permissions-Policy can block needed browser APIs. Always test in a staging environment first.
Q. How do I add security headers in Nginx?
A. Add add_header directives in the server block: add_header X-Content-Type-Options 'nosniff'; add_header X-Frame-Options 'DENY'; add_header Strict-Transport-Security 'max-age=31536000; includeSubDomains; preload';
Key takeaways
  • Security headers tell browsers to enforce security protections.
  • Key headers: CSP, HSTS, X-Content-Type-Options, X-Frame-Options, Referrer-Policy, Permissions-Policy.
  • Test your headers with securityheaders.com or Mozilla Observatory.
  • Aim for grade A/A+ on both tools. Test headers after every deployment.
How Atomic Glue helps

Atomic Glue configures and audits security headers on all deployments, targets A+ grade on securityheaders.com, and integrates header testing into CI/CD. Trust & Security.

Get in touch

Security headers are HTTP response headers that instruct browsers to enable security protections. They prevent common attacks including XSS, clickjacking, MIME sniffing, and protocol downgrades.

Definition

Security headers are HTTP response headers that a web server sends to a browser to enable security features and restrictions. They form a critical layer of defense-in-depth for any web application. Key security headers include: Content-Security-Policy (controls resource loading), Strict-Transport-Security (forces HTTPS), X-Content-Type-Options (prevents MIME sniffing), X-Frame-Options (prevents clickjacking), Referrer-Policy (controls referrer information), and Permissions-Policy (controls browser features). Tools like securityheaders.com and Mozilla Observatory scan and grade a site's security header implementation.

Essential Security Headers

Content-Security-Policy (CSP): Controls which resources can be loaded. Most powerful security header. Strict-Transport-Security (HSTS): Forces HTTPS connections. X-Content-Type-Options: nosniff: Prevents MIME type sniffing attacks. X-Frame-Options: DENY or SAMEORIGIN: Prevents clickjacking by controlling iframe embedding. Referrer-Policy: Controls how much referrer information is sent with requests. Permissions-Policy (formerly Feature-Policy): Controls which browser APIs and features the page can use (camera, microphone, geolocation).

Security Header Scoring

securityheaders.com provides an A-to-F rating for a site's security headers. An A+ rating requires: Strict-Transport-Security (with preload), Content-Security-Policy (or proper X-Frame-Options), X-Content-Type-Options, and Referrer-Policy. Mozilla Observatory provides a similar grading system with more granular scoring. Achieving a high score on these tools is a good indicator of baseline web security, but headers must be configured correctly for your specific application, not just for the score.

Common Misconfigurations

Setting CSP with 'unsafe-inline' effectively disables XSS protection. Setting HSTS with a short max-age provides minimal protection. Omitting the 'includeSubDomains' flag on HSTS leaves subdomains exposed to downgrade. Setting X-Frame-Options when CSP's frame-ancestors already controls framing (use one or the other). Missing the Secure flag on cookies. Setting Permissions-Policy too restrictively (blocking legitimate features) or not at all.

Note

Use securityheaders.com and Mozilla Observatory to test your site's headers. Aim for grade A/A+ on both. Test headers after every deployment to catch regressions.

Common questions

Q: What is the single most important security header?

A: Content-Security-Policy (CSP) with a strict, nonce-based policy is the most powerful single header, as it prevents XSS and data injection attacks. HSTS is a close second for ensuring encrypted connections.

Q: Can security headers break my website?

A: Yes. CSP can block legitimate resources. X-Frame-Options can break valid iframe embeds. Permissions-Policy can block needed browser APIs. Always test in a staging environment first.

Q: How do I add security headers in Nginx?

A: Add add_header directives in the server block: add_header X-Content-Type-Options 'nosniff'; add_header X-Frame-Options 'DENY'; add_header Strict-Transport-Security 'max-age=31536000; includeSubDomains; preload';

Key takeaways:

  • Security headers tell browsers to enforce security protections.

  • Key headers: CSP, HSTS, X-Content-Type-Options, X-Frame-Options, Referrer-Policy, Permissions-Policy.

  • Test your headers with securityheaders.com or Mozilla Observatory.

  • Aim for grade A/A+ on both tools. Test headers after every deployment.

Schedule a call

30 min · Video call

1
Date
2
Time
3
Details