Guides

HTTP security headers explained: HSTS, CSP and the rest

Security headers are instructions your web server sends with every page. They cost nothing to add, and each one closes a specific class of attack — if you set it to a sensible value.

Last reviewed: 2026-09-30

What are HTTP security headers?

They are HTTP response headers that tell the browser how strictly to treat your site: only over HTTPS, only with scripts from approved sources, never inside someone else's frame, and so on. The browser enforces them; your server only has to send them.

Strict-Transport-Security (HSTS)

HSTS tells the browser to use HTTPS for your domain for a period of time, even if someone types http:// or follows an old link. It stops SSL-stripping on hostile networks. Start with a short max-age, confirm every subdomain works over HTTPS, then raise it. Only add includeSubDomains and preload when you are sure — preload is hard to undo.

Strict-Transport-Security: max-age=31536000; includeSubDomains

Content-Security-Policy (CSP)

CSP lists where scripts, styles, images and frames may be loaded from. A good policy turns most cross-site scripting (XSS) bugs from "attacker runs code" into "browser refuses". Policies with 'unsafe-inline' or wildcards in script-src give much weaker protection.

Roll it out safely: send Content-Security-Policy-Report-Only first, watch the violation reports, fix legitimate sources, and only then switch to the enforcing header. Korantix itself runs CSP in report-only mode while it prepares nonce-based enforcement.

Content-Security-Policy: default-src 'self'; script-src 'self'; object-src 'none'; base-uri 'self'; frame-ancestors 'none'

The short, easy wins

  • X-Content-Type-Options: nosniff — stops the browser from guessing a file's type (MIME sniffing).
  • X-Frame-Options: DENY (or CSP frame-ancestors 'none') — prevents clickjacking by forbidding other sites from framing your pages.
  • Referrer-Policy: strict-origin-when-cross-origin — keeps full URLs, which may contain tokens or search terms, from leaking to other sites.
  • Permissions-Policy — switches off browser features you do not use, such as camera, microphone or geolocation.

How to verify

Check the headers on the real production URL, not a local build: CDNs, proxies and hosting platforms often add or strip headers. Run the Korantix Security Headers Checker, or look at one response from the command line:

curl -sI https://example.com | grep -iE 'strict-transport|content-security|x-frame|x-content-type|referrer-policy|permissions-policy'

What headers cannot do

Headers reduce the impact of bugs; they do not fix them. A strict CSP will not stop SQL injection, and HSTS will not help if the certificate itself is wrong. Treat them as one layer next to secure code, patched software and a valid TLS certificate.

Check this on your domain →