HTTP security headers explained: HSTS, CSP and the rest
Security headers are instructions your web server sends with every page. They cost nothing to add, and each one closes a specific class of attack — if you set it to a sensible value.
Last reviewed: 2026-09-30
What are HTTP security headers?
They are HTTP response headers that tell the browser how strictly to treat your site: only over HTTPS, only with scripts from approved sources, never inside someone else's frame, and so on. The browser enforces them; your server only has to send them.
Strict-Transport-Security (HSTS)
HSTS tells the browser to use HTTPS for your domain for a period of time, even if someone types http:// or follows an old link. It stops SSL-stripping on hostile networks. Start with a short max-age, confirm every subdomain works over HTTPS, then raise it. Only add includeSubDomains and preload when you are sure — preload is hard to undo.
Strict-Transport-Security: max-age=31536000; includeSubDomainsContent-Security-Policy (CSP)
CSP lists where scripts, styles, images and frames may be loaded from. A good policy turns most cross-site scripting (XSS) bugs from "attacker runs code" into "browser refuses". Policies with 'unsafe-inline' or wildcards in script-src give much weaker protection.
Roll it out safely: send Content-Security-Policy-Report-Only first, watch the violation reports, fix legitimate sources, and only then switch to the enforcing header. Korantix itself runs CSP in report-only mode while it prepares nonce-based enforcement.
Content-Security-Policy: default-src 'self'; script-src 'self'; object-src 'none'; base-uri 'self'; frame-ancestors 'none'The short, easy wins
- X-Content-Type-Options: nosniff — stops the browser from guessing a file's type (MIME sniffing).
- X-Frame-Options: DENY (or CSP frame-ancestors 'none') — prevents clickjacking by forbidding other sites from framing your pages.
- Referrer-Policy: strict-origin-when-cross-origin — keeps full URLs, which may contain tokens or search terms, from leaking to other sites.
- Permissions-Policy — switches off browser features you do not use, such as camera, microphone or geolocation.
How to verify
Check the headers on the real production URL, not a local build: CDNs, proxies and hosting platforms often add or strip headers. Run the Korantix Security Headers Checker, or look at one response from the command line:
curl -sI https://example.com | grep -iE 'strict-transport|content-security|x-frame|x-content-type|referrer-policy|permissions-policy'What headers cannot do
Headers reduce the impact of bugs; they do not fix them. A strict CSP will not stop SQL injection, and HSTS will not help if the certificate itself is wrong. Treat them as one layer next to secure code, patched software and a valid TLS certificate.