Setting HTTP response headers correctly is one of the cheapest security improvements you can make to a web application. A few lines of configuration make an entire class of browser-level attacks much harder. But the same headers, configured badly, can also break production. In this post we cover what each header does and how to roll them out gradually.
Strict-Transport-Security (HSTS)
Tells the browser: “only connect to this site over HTTPS.” Once it is in effect, the browser refuses plain HTTP connections when someone attempts to intercept traffic.
A word of caution: includeSubDomains and preload are powerful but hard to undo. Don’t add includeSubDomains until you are sure every one of your subdomains serves HTTPS. Start with a short max-age, and only extend it once you’ve confirmed everything works.
Content-Security-Policy (CSP)
The most powerful header, and the one that demands the most care. It tells the browser which sources it may load scripts, styles and images from. Configured correctly, it largely prevents an injected script from running.
Switching CSP straight to enforcing mode will break your site. The right approach is:
- Ship it first in report-only mode.
- Use the reports to see which resources would be blocked under real traffic.
- Tighten the policy based on what you observe.
- Switch to enforcing mode only once the site runs without issues.
X-Frame-Options and frame-ancestors
Prevents your site from being covertly embedded inside another page to trick users into clicking the wrong thing. The modern approach is to get the same protection from the CSP frame-ancestors directive. Sending both covers older and newer browsers alike.
X-Content-Type-Options
It has a single value and turns off the browser’s attempts to guess the content type. In some cases that guessing can lead to malicious content being misinterpreted. It has virtually no side effects and is safe to apply.
Referrer-Policy and Permissions-Policy
Referrer-Policy controls how much URL information leaks when users navigate to other sites. Permissions-Policy restricts who can access browser capabilities such as the camera and location. Both shrink your privacy surface and carry little risk.
A gradual rollout plan
- Start with the ones that have no side effects:
X-Content-Type-Options,Referrer-Policy. - Add framing protection:
X-Frame-Optionsandframe-ancestors. - Enable HSTS with a short max-age, verify, then extend it.
- Launch CSP in report-only mode, refine it against real traffic, and move it to enforcing mode last.
Measure, don’t guess
After making changes, verify that your headers are actually being applied. Enter your domain in the free test in our Pentest Tools section to score your headers and see everything that’s missing on a single screen.