HTTP security headers are lines your web server adds to every response telling browsers how to behave when handling your content. They block entire categories of attacks — for free. Most sites have none of them configured.
Check Your Headers Now
Use Anonymiz HTTP Security Headers Checker to scan any domain and see which headers are present and which are missing. It grades your site from A to F.
The Essential Headers
Strict-Transport-Security (HSTS)
Forces browsers to only connect via HTTPS for a specified period. Prevents SSL stripping attacks.
Strict-Transport-Security: max-age=31536000; includeSubDomains; preload
Content-Security-Policy (CSP)
The most powerful header. Defines which sources of scripts, styles, images and other resources the browser is allowed to load. Blocks XSS attacks at the browser level.
Content-Security-Policy: default-src 'self'; script-src 'self' 'nonce-xyz'
X-Frame-Options
Prevents your page from being embedded in an iframe on another site (clickjacking protection).
X-Frame-Options: DENY
X-Content-Type-Options
Stops browsers from MIME-sniffing responses. Prevents drive-by downloads disguised as a different content type.
X-Content-Type-Options: nosniff
Referrer-Policy
Controls what referrer information is sent with outbound requests.
Referrer-Policy: strict-origin-when-cross-origin
Permissions-Policy
Controls access to browser features like camera, microphone, geolocation and payment APIs.
Permissions-Policy: camera=(), microphone=(), geolocation=()
How to Add Headers in Apache (.htaccess)
Header always set Strict-Transport-Security "max-age=31536000; includeSubDomains"
Header always set X-Frame-Options "DENY"
Header always set X-Content-Type-Options "nosniff"
How to Add Headers in Nginx
add_header Strict-Transport-Security "max-age=31536000; includeSubDomains" always;
add_header X-Frame-Options "DENY" always;
add_header X-Content-Type-Options "nosniff" always;
Getting an A Grade
To score an A on the security headers checker, you need at minimum: HSTS, CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, and Permissions-Policy. Most shared hosting supports these via .htaccess or server config.
CSP deserves special attention because getting it wrong either does nothing (too permissive) or breaks your site (too strict). A common middle ground is starting with Content-Security-Policy-Report-Only, which logs violations to the browser console without actually blocking anything, letting you see what a real CSP would break before enforcing it. Many sites launch a broken CSP because they test it against their own browsing session, which has cached scripts and no ad blockers, then discover it silently breaks functionality for visitors with different setups.
X-Frame-Options and the newer frame-ancestors CSP directive both exist specifically to prevent clickjacking, where a malicious site embeds yours in an invisible iframe and tricks users into clicking something they didn't intend to. Setting either header to deny framing except from trusted origins is one of the highest-value, lowest-effort security headers to add, since clickjacking exploits are otherwise straightforward to build against any unprotected page.


