Decloak is an AI-powered web security intelligence platform that scans a site's HTTP/TLS posture, JavaScript, and third-party scripts to produce a report anyone can read. This guide is part of Decloak's library of practical, source-backed security guidance.
In this guide
What are security headers?
Security headers are HTTP response headers that tell browsers to enforce specific security policies for the content they receive. They are optional but widely recommended because browsers automatically apply the rules, providing a layer of defense in depth without changing application code.
Which security headers protect against the most common web attacks?
The most protective headers are Strict-Transport-Security (HSTS), Content-Security-Policy (CSP), X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, and cache directives. The table below shows each header, its primary protection, and a typical value.
| Header | Primary protection | Typical value |
|---|---|---|
| Strict-Transport-Security (HSTS) | Forces HTTPS, prevents protocol downgrade attacks | max-age=31536000; includeSubDomains; preload |
| Content-Security-Policy (CSP) | Limits sources for scripts, styles, images, reducing XSS and data injection risk | default-src 'self'; script-src 'self' https://trusted.cdn.com; object-src 'none' |
| X-Frame-Options | Blocks clickjacking by controlling framing | DENY or SAMEORIGIN |
| X-Content-Type-Options | Stops MIME type sniffing which can lead to script execution | nosniff |
| Referrer-Policy | Controls how much referrer information is sent, limiting data leakage | strict-origin-when-cross-origin |
| Permissions-Policy | Disables or limits powerful browser features like camera, geolocation | geolocation=(), camera=() |
| Cross-Origin-Resource-Policy (CORP) / Cross-Origin-Opener-Policy (COOP) / Cross-Origin-Embedder-Policy (COEP) | Isolates resources and browsing contexts to mitigate side - channel attacks (e.g., XS - Leak) | cross-origin-resource-policy: same-site, cross-origin-opener-policy: same-origin |
| Clear-Site-Data | Instructs the browser to clear cookies, storage, cache on logout or breach response | "cookies" "storage" |
| Cache-Control / Pragma | Prevents shared caches from storing sensitive responses | no-store, no-cache, must-revalidate |
How do I add security headers to my web server?
Add the required headers by editing your server configuration or adding middleware in your application code. The steps are:
- Identify the server technology - Apache, Nginx, IIS, Node/Express, etc.
- Edit the configuration - add
Header set(Apache),add_header(Nginx), or middleware (Express) for each header you need.
- Apache example:
Header always set Strict-Transport-Security "max-age=31536000; includeSubDomains; preload"
Header always set X-Content-Type-Options "nosniff"
Header always set X-Frame-Options "DENY"
- Nginx example:
add_header Strict-Transport-Security "max-age=31536000; includeSubDomains; preload" always;
add_header Content-Security-Policy "default-src 'self'; script-src 'self' https://cdn.example.com; object-src 'none'";
add_header X-Frame-Options "DENY";
- Express (Node.js) example:
app.use((req, res, next) => {
res.setHeader('Strict-Transport-Security', 'max-age=31536000; includeSubDomains; preload');
res.setHeader('X-Content-Type-Options', 'nosniff');
res.setHeader('X-Frame-Options', 'DENY');
next();
});
- Test locally - run
curl -I https://yourdomain.comto verify each header appears. - Deploy and monitor - watch for browser console warnings and adjust CSP as needed.
How can Decloak verify my security headers?
Decloak’s free scan checks header presence and configuration via Layer 1 (HTTP/TLS security posture). The scan runs in about 15 seconds, returns a graded, shareable report, and lists any missing or mis - configured headers with concrete remediation guidance. Because the scan is unauthenticated and targets the public endpoint, you get immediate proof that your production site delivers the expected headers.
Key takeaways
- Security headers are simple HTTP directives that let browsers enforce security policies without code changes.
- The most critical headers are HSTS, CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, and cache - control directives.
- Adding headers is a matter of a few lines in your server config or middleware; always test with
curl -I. - Decloak’s free scan validates header presence and correctness in seconds, giving you immediate proof that your site follows best - practice defenses.
Related guides
How to Fix a Missing Content - Security - Policy Header
Learn concrete steps to add, test, and harden a Content - Security - Policy header, from server configuration to iterative reporting and verification.
Is HTTP 1.1 a security risk?
HTTP 1.1 is not a direct vulnerability, but its plain - text design and parsing ambiguities can create attack surfaces that need mitigation, especially when not used over TLS.
Is JavaScript a security risk?
JavaScript can be a major attack surface because injected scripts run with the same privileges as the page, but proper sanitization, CSP, and safe frameworks eliminate most risks.