Back to Guides
Guide6 October 2026

How to Analyze and Harden Your Site’s Security Headers

Decloak is an AI-powered web security intelligence platform that scans a site's HTTP/TLS posture, JavaScript, and third-party scripts to produce a report anyone can read. This guide is part of Decloak's library of practical, source-backed security guidance.

In this guide
  1. Key takeaways
  2. What are security headers and why should I care?
  3. Which security headers are essential for modern browsers?
  4. Which headers are legacy or discouraged?
  5. How do I configure each essential header in common web servers?
  6. How can I verify my headers are correctly set?
  7. What are common pitfalls when implementing security headers?
  8. Should I keep or drop informational headers like Server?
  9. Quick checklist for a secure header baseline

Key takeaways


What are security headers and why should I care?

Security headers are HTTP response directives that tell browsers how to treat content, reducing the attack surface for XSS, click - jacking, protocol - downgrade, and data - leakage. Implementing them correctly adds defense - in - depth without changing any application code.

Which security headers are essential for modern browsers?

The core set of widely supported headers that provide real protection are:

HeaderSecure value examplePrimary protection
Strict-Transport-Security (HSTS)max-age=63072000; includeSubDomains; preloadForces HTTPS, stops downgrade attacks
Content-Security-Policy (CSP)default-src 'self'; script-src 'self' https://cdn.example.com; object-src 'none'Blocks injection of malicious scripts
X-Content-Type-OptionsnosniffPrevents MIME - type sniffing
Referrer-Policystrict-origin-when-cross-originLimits referrer leakage
Permissions-Policygeolocation=(), camera=(), microphone=()Disables unused browser features
Cross-Origin-Opener-Policy (COOP)same-originIsolates top - level documents
Cross-Origin-Embedder-Policy (COEP)require-corpForces cross - origin resources to opt - in
Cross-Origin-Resource-Policy (CORP)same-siteRestricts who can load a resource
Set - Cookie flagsHttpOnly; Secure; SameSite=StrictProtects session cookies

Which headers are legacy or discouraged?

Headers that no longer provide benefit or are actively discouraged:

HeaderRecommended action
X - XSS - ProtectionSet to 0 or remove - CSP is preferred
Expect - CTRemove - browsers enforce CT elsewhere
Public - Key - Pins (HPKP)Remove - unsupported since 2018
Server / X - Powered - By / X - AspNet - VersionStrip or mask to reduce fingerprinting

How do I configure each essential header in common web servers?

Apache

Header always set Strict-Transport-Security "max-age=63072000; includeSubDomains; preload"
Header set Content-Security-Policy "default-src 'self'; script-src 'self' https://cdn.example.com; object-src 'none'"
Header set X-Content-Type-Options "nosniff"
Header set Referrer-Policy "strict-origin-when-cross-origin"
Header set Permissions-Policy "geolocation=(), camera=(), microphone=()"
Header set Cross-Origin-Opener-Policy "same-origin"
Header set Cross-Origin-Embedder-Policy "require-corp"
Header set Cross-Origin-Resource-Policy "same-site"

Nginx

add_header Strict-Transport-Security "max-age=63072000; includeSubDomains; preload" always;
add_header Content-Security-Policy "default-src 'self'; script-src 'self' https://cdn.example.com; object-src 'none'";
add_header X-Content-Type-Options "nosniff";
add_header Referrer-Policy "strict-origin-when-cross-origin";
add_header Permissions-Policy "geolocation=(), camera=(), microphone=()";
add_header Cross-Origin-Opener-Policy "same-origin";
add_header Cross-Origin-Embedder-Policy "require-corp";
add_header Cross-Origin-Resource-Policy "same-site";

Express (Node.js)

app.use((req, res, next) => {
 res.setHeader('Strict-Transport-Security', 'max-age=63072000; includeSubDomains; preload');
 res.setHeader('Content-Security-Policy', "default-src 'self'; script-src 'self' https://cdn.example.com; object-src 'none'");
 res.setHeader('X-Content-Type-Options', 'nosniff');
 res.setHeader('Referrer-Policy', 'strict-origin-when-cross-origin');
 res.setHeader('Permissions-Policy', 'geolocation=(), camera=(), microphone=()');
 res.setHeader('Cross-Origin-Opener-Policy', 'same-origin');
 res.setHeader('Cross-Origin-Embedder-Policy', 'require-corp');
 res.setHeader('Cross-Origin-Resource-Policy', 'same-site');
 next();
});

How can I verify my headers are correctly set?

Run Decloak’s free scan on any URL - it requires no account and returns a graded report in about 15 seconds. The scan’s static HTML analysis layer flags missing or mis - configured security headers, while the rendered-page network behaviour layer confirms they are actually sent over HTTPS.

  1. Open https://app.decloak.com (or the public scan page).
  2. Enter the target URL and start the scan.
  3. Review the “HTTP/TLS security posture” section for HSTS and TLS settings, then scroll to the header findings.
  4. Each finding shows the header name, the value observed, and a concrete remediation tip.

Because the free scan covers all eight core layers, you also get visibility into related issues such as insecure cookies or dangerous JavaScript patterns that could undermine your header policies.

What are common pitfalls when implementing security headers?

Should I keep or drop informational headers like Server?

Removing or masking these headers reduces the data an attacker can use for fingerprinting. In Apache you can add ServerTokens Prod and ServerSignature Off; in Nginx server_tokens off;. For Express, use app.disable('x-powered-by');.


Quick checklist for a secure header baseline

Run a Decloak free scan after each change to confirm the headers are present and correctly valued.

Free security scan

See what's actually exposed on your site.

Decloak's free scan runs in about 15 seconds, no account required, and covers:

  • HTTP/TLS security posture
  • JavaScript CVEs
  • Exposed Supabase/Lovable/Base44 misconfigurations
  • AI-written executive summary