Back to Guides
Guide5 October 2026

What are security headers and why should you use them?

Decloak is an AI-powered web security intelligence platform that scans a site's HTTP/TLS posture, JavaScript, and third-party scripts to produce a report anyone can read. This guide is part of Decloak's library of practical, source-backed security guidance.

In this guide
  1. What are security headers?
  2. Which security headers protect against the most common web attacks?
  3. How do I add security headers to my web server?
  4. How can Decloak verify my security headers?
  5. Key takeaways

What are security headers?

Security headers are HTTP response headers that tell browsers to enforce specific security policies for the content they receive. They are optional but widely recommended because browsers automatically apply the rules, providing a layer of defense in depth without changing application code.

Which security headers protect against the most common web attacks?

The most protective headers are Strict-Transport-Security (HSTS), Content-Security-Policy (CSP), X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, and cache directives. The table below shows each header, its primary protection, and a typical value.

HeaderPrimary protectionTypical value
Strict-Transport-Security (HSTS)Forces HTTPS, prevents protocol downgrade attacksmax-age=31536000; includeSubDomains; preload
Content-Security-Policy (CSP)Limits sources for scripts, styles, images, reducing XSS and data injection riskdefault-src 'self'; script-src 'self' https://trusted.cdn.com; object-src 'none'
X-Frame-OptionsBlocks clickjacking by controlling framingDENY or SAMEORIGIN
X-Content-Type-OptionsStops MIME type sniffing which can lead to script executionnosniff
Referrer-PolicyControls how much referrer information is sent, limiting data leakagestrict-origin-when-cross-origin
Permissions-PolicyDisables or limits powerful browser features like camera, geolocationgeolocation=(), camera=()
Cross-Origin-Resource-Policy (CORP) / Cross-Origin-Opener-Policy (COOP) / Cross-Origin-Embedder-Policy (COEP)Isolates resources and browsing contexts to mitigate side - channel attacks (e.g., XS - Leak)cross-origin-resource-policy: same-site, cross-origin-opener-policy: same-origin
Clear-Site-DataInstructs the browser to clear cookies, storage, cache on logout or breach response"cookies" "storage"
Cache-Control / PragmaPrevents shared caches from storing sensitive responsesno-store, no-cache, must-revalidate

How do I add security headers to my web server?

Add the required headers by editing your server configuration or adding middleware in your application code. The steps are:

  1. Identify the server technology - Apache, Nginx, IIS, Node/Express, etc.
  2. Edit the configuration - add Header set (Apache), add_header (Nginx), or middleware (Express) for each header you need.
Header always set Strict-Transport-Security "max-age=31536000; includeSubDomains; preload"
Header always set X-Content-Type-Options "nosniff"
Header always set X-Frame-Options "DENY"
add_header Strict-Transport-Security "max-age=31536000; includeSubDomains; preload" always;
add_header Content-Security-Policy "default-src 'self'; script-src 'self' https://cdn.example.com; object-src 'none'";
add_header X-Frame-Options "DENY";
app.use((req, res, next) => {
res.setHeader('Strict-Transport-Security', 'max-age=31536000; includeSubDomains; preload');
res.setHeader('X-Content-Type-Options', 'nosniff');
res.setHeader('X-Frame-Options', 'DENY');
next();
});
  1. Test locally - run curl -I https://yourdomain.com to verify each header appears.
  2. Deploy and monitor - watch for browser console warnings and adjust CSP as needed.

How can Decloak verify my security headers?

Decloak’s free scan checks header presence and configuration via Layer 1 (HTTP/TLS security posture). The scan runs in about 15 seconds, returns a graded, shareable report, and lists any missing or mis - configured headers with concrete remediation guidance. Because the scan is unauthenticated and targets the public endpoint, you get immediate proof that your production site delivers the expected headers.

Key takeaways

Free security scan

See what's actually exposed on your site.

Decloak's free scan runs in about 15 seconds, no account required, and covers:

  • HTTP/TLS security posture
  • JavaScript CVEs
  • Exposed Supabase/Lovable/Base44 misconfigurations
  • AI-written executive summary