Decloak is an AI-powered web security intelligence platform that scans a site's HTTP/TLS posture, JavaScript, and third-party scripts to produce a report anyone can read. This guide is part of Decloak's library of practical, source-backed security guidance.
In this guide
- Key takeaways
- What are security headers and why should I care?
- Which security headers are essential for modern browsers?
- Which headers are legacy or discouraged?
- How do I configure each essential header in common web servers?
- How can I verify my headers are correctly set?
- What are common pitfalls when implementing security headers?
- Should I keep or drop informational headers like Server?
- Quick checklist for a secure header baseline
Key takeaways
- The essential modern headers are Strict-Transport-Security, Content-Security-Policy, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, Cross-Origin-Opener-Policy, Cross-Origin-Embedder-Policy, Cross-Origin-Resource-Policy, and proper Secure/HttpOnly/SameSite cookie flags.
- Legacy or discouraged headers include X-XSS-Protection, Expect-CT, Public-Key-Pins; they should be removed or set to neutral values.
- Informational headers like Server or X-Powered-By should be stripped to reduce fingerprinting.
- Decloak’s free scan checks all eight core layers, including static HTML analysis and rendered-page network behaviour, which surface missing or mis - configured security headers in about 15 seconds.
- Use a comparison table to decide which headers to keep, adjust, or drop for your application.
What are security headers and why should I care?
Security headers are HTTP response directives that tell browsers how to treat content, reducing the attack surface for XSS, click - jacking, protocol - downgrade, and data - leakage. Implementing them correctly adds defense - in - depth without changing any application code.
Which security headers are essential for modern browsers?
The core set of widely supported headers that provide real protection are:
| Header | Secure value example | Primary protection |
|---|---|---|
| Strict-Transport-Security (HSTS) | max-age=63072000; includeSubDomains; preload | Forces HTTPS, stops downgrade attacks |
| Content-Security-Policy (CSP) | default-src 'self'; script-src 'self' https://cdn.example.com; object-src 'none' | Blocks injection of malicious scripts |
| X-Content-Type-Options | nosniff | Prevents MIME - type sniffing |
| Referrer-Policy | strict-origin-when-cross-origin | Limits referrer leakage |
| Permissions-Policy | geolocation=(), camera=(), microphone=() | Disables unused browser features |
| Cross-Origin-Opener-Policy (COOP) | same-origin | Isolates top - level documents |
| Cross-Origin-Embedder-Policy (COEP) | require-corp | Forces cross - origin resources to opt - in |
| Cross-Origin-Resource-Policy (CORP) | same-site | Restricts who can load a resource |
| Set - Cookie flags | HttpOnly; Secure; SameSite=Strict | Protects session cookies |
Which headers are legacy or discouraged?
Headers that no longer provide benefit or are actively discouraged:
| Header | Recommended action |
|---|---|
| X - XSS - Protection | Set to 0 or remove - CSP is preferred |
| Expect - CT | Remove - browsers enforce CT elsewhere |
| Public - Key - Pins (HPKP) | Remove - unsupported since 2018 |
| Server / X - Powered - By / X - AspNet - Version | Strip or mask to reduce fingerprinting |
How do I configure each essential header in common web servers?
Apache
Header always set Strict-Transport-Security "max-age=63072000; includeSubDomains; preload"
Header set Content-Security-Policy "default-src 'self'; script-src 'self' https://cdn.example.com; object-src 'none'"
Header set X-Content-Type-Options "nosniff"
Header set Referrer-Policy "strict-origin-when-cross-origin"
Header set Permissions-Policy "geolocation=(), camera=(), microphone=()"
Header set Cross-Origin-Opener-Policy "same-origin"
Header set Cross-Origin-Embedder-Policy "require-corp"
Header set Cross-Origin-Resource-Policy "same-site"
Nginx
add_header Strict-Transport-Security "max-age=63072000; includeSubDomains; preload" always;
add_header Content-Security-Policy "default-src 'self'; script-src 'self' https://cdn.example.com; object-src 'none'";
add_header X-Content-Type-Options "nosniff";
add_header Referrer-Policy "strict-origin-when-cross-origin";
add_header Permissions-Policy "geolocation=(), camera=(), microphone=()";
add_header Cross-Origin-Opener-Policy "same-origin";
add_header Cross-Origin-Embedder-Policy "require-corp";
add_header Cross-Origin-Resource-Policy "same-site";
Express (Node.js)
app.use((req, res, next) => {
res.setHeader('Strict-Transport-Security', 'max-age=63072000; includeSubDomains; preload');
res.setHeader('Content-Security-Policy', "default-src 'self'; script-src 'self' https://cdn.example.com; object-src 'none'");
res.setHeader('X-Content-Type-Options', 'nosniff');
res.setHeader('Referrer-Policy', 'strict-origin-when-cross-origin');
res.setHeader('Permissions-Policy', 'geolocation=(), camera=(), microphone=()');
res.setHeader('Cross-Origin-Opener-Policy', 'same-origin');
res.setHeader('Cross-Origin-Embedder-Policy', 'require-corp');
res.setHeader('Cross-Origin-Resource-Policy', 'same-site');
next();
});
How can I verify my headers are correctly set?
Run Decloak’s free scan on any URL - it requires no account and returns a graded report in about 15 seconds. The scan’s static HTML analysis layer flags missing or mis - configured security headers, while the rendered-page network behaviour layer confirms they are actually sent over HTTPS.
- Open https://app.decloak.com (or the public scan page).
- Enter the target URL and start the scan.
- Review the “HTTP/TLS security posture” section for HSTS and TLS settings, then scroll to the header findings.
- Each finding shows the header name, the value observed, and a concrete remediation tip.
Because the free scan covers all eight core layers, you also get visibility into related issues such as insecure cookies or dangerous JavaScript patterns that could undermine your header policies.
What are common pitfalls when implementing security headers?
- Overly strict CSP: Blocking legitimate third - party scripts will break functionality. Start with
default-src 'self'and add required origins incrementally. - Missing subdomain coverage in HSTS: Forgetting
includeSubDomainsleaves HTTP endpoints vulnerable. - Setting
X - XSS - Protection: 1; mode=block: Modern browsers ignore it, and it can give a false sense of security. Use CSP instead. - Inconsistent cookie flags: Setting
SecurewithoutSameSitecan still allow cross - site request forgery. Apply all three attributes together. - Deploying headers only on the main domain: Reverse proxies or CDN edge nodes may strip headers. Verify the final response with a tool like Decloak.
Should I keep or drop informational headers like Server?
Removing or masking these headers reduces the data an attacker can use for fingerprinting. In Apache you can add ServerTokens Prod and ServerSignature Off; in Nginx server_tokens off;. For Express, use app.disable('x-powered-by');.
Quick checklist for a secure header baseline
- HSTS with max - age ≥ 2 years, includeSubDomains, preload flag
- CSP that disables inline scripts and eval
- X-Content-Type-Options set to
nosniff - Referrer-Policy set to
strict-origin-when-cross-origin - Permissions-Policy disables all unused features
- COOP, COEP, and CORP configured for cross - origin isolation if needed
- Secure, HttpOnly, SameSite=Strict on all session cookies
- Legacy and informational headers removed or neutralized
Run a Decloak free scan after each change to confirm the headers are present and correctly valued.
Related guides
How to Fix a Missing Content - Security - Policy Header
Learn concrete steps to add, test, and harden a Content - Security - Policy header, from server configuration to iterative reporting and verification.
Is HTTP 1.1 a security risk?
HTTP 1.1 is not a direct vulnerability, but its plain - text design and parsing ambiguities can create attack surfaces that need mitigation, especially when not used over TLS.
Is JavaScript a security risk?
JavaScript can be a major attack surface because injected scripts run with the same privileges as the page, but proper sanitization, CSP, and safe frameworks eliminate most risks.