HTTP Security Headers
HTTP response headers that instruct browsers to enable protective behaviours, such as enforcing HTTPS, restricting content sources, preventing framing and limiting information leakage, as a low-cost layer of web defence.
Commonly recommended headers include Strict-Transport-Security to enforce HTTPS, Content-Security-Policy to restrict content sources, X-Content-Type-Options set to nosniff to stop MIME-type sniffing, the frame-ancestors directive or X-Frame-Options to prevent clickjacking, Referrer-Policy to limit URL leakage to other sites, and Permissions-Policy to restrict browser features such as the camera, microphone and geolocation. Cross-origin isolation headers such as Cross-Origin-Opener-Policy add further protection.
Security headers are set in web server, reverse proxy, CDN or application configuration and apply across a whole site, so they provide broad protection for modest effort. Their absence is a frequent finding in security scans and penetration tests, and the OWASP Secure Headers Project documents current recommendations. Headers that reveal software versions, such as detailed Server or X-Powered-By values, are often removed to reduce information disclosure.
Headers must be configured carefully: a strict HSTS policy or CSP can break functionality if introduced without testing, and outdated headers such as X-XSS-Protection are deprecated and best disabled or omitted. Headers support secure coding but do not replace it, and each should be verified in all environments, including on error pages and API responses.
Key points
- Low-effort controls that activate built-in browser protections.
- Key headers include HSTS, CSP, X-Content-Type-Options and Referrer-Policy.
- X-XSS-Protection is deprecated and should not be relied on.
- Strict policies should be tested before enforcement to avoid breaking functionality.
Where AiVibe comes in
AiVedha.ai's automated website security audit covers HTTP headers among more than 170 checks, with severity ratings and remediation steps in its report.
Related terms
- HTTP Strict Transport Security (HSTS)Cybersecurity & Compliance
- Content Security Policy (CSP)Cybersecurity & Compliance
- Cross-Origin Resource Sharing (CORS)Cybersecurity & Compliance
- Cookie Security AttributesCybersecurity & Compliance
- Security MisconfigurationCybersecurity & Compliance