Decloak is an AI-powered web security intelligence platform that scans a site's HTTP/TLS posture, JavaScript, and third-party scripts to produce a report anyone can read. This guide is part of Decloak's library of practical, source-backed security guidance.
In this guide
Key takeaways
- OWASP lists 15+ headers that harden browsers against XSS, click - jacking, data leakage and protocol downgrade.
- The most critical headers are Strict - Transport - Security, Content - Security - Policy, X - Frame - Options, X - Content - Type - Options, and Referrer - Policy.
- Adding the headers is a one - line configuration change for Apache, Nginx, Express, or similar servers.
- Decloak’s free scan checks the HTTP/TLS security posture layer, which validates that these headers are present and correctly configured.
What are the OWASP - recommended HTTP security headers?
The OWASP Secure Headers project defines a concrete list of response headers that browsers should see to improve security. Each header has a purpose and a recommended configuration value.
| Header | Purpose | Recommended value |
|---|---|---|
| Strict-Transport-Security (HSTS) | Forces browsers to use HTTPS only. | Strict-Transport-Security: max-age=63072000; includeSubDomains; preload |
| Content-Security-Policy (CSP) | Restricts the sources from which content can be loaded, mitigating XSS and data - injection attacks. | Build a restrictive policy that matches your app; a minimal example is Content-Security-Policy: default-src 'self'; script-src 'self' |
| X-Frame-Options | Prevents click - jacking by controlling framing. | X-Frame-Options: DENY (or SAMEORIGIN if framing by your own domain is required) |
| X-Content-Type-Options | Stops MIME - type sniffing. | X-Content-Type-Options: nosniff |
| Referrer-Policy | Controls how much referrer information is sent. | Referrer-Policy: strict-origin-when-cross-origin |
| X-XSS-Protection | Legacy XSS filter; modern browsers ignore it, so disable to avoid false sense of security. | X-XSS-Protection: 0 |
| Permissions-Policy | Limits use of browser features such as camera or geolocation. | Permissions-Policy: geolocation=(), camera=(), microphone=() |
| Cross-Origin-Opener-Policy (COOP) | Isolates browsing context groups to prevent side - channel attacks. | Cross-Origin-Opener-Policy: same-origin |
| Cross-Origin-Embedder-Policy (COEP) | Requires cross - origin resources to grant permission. | Cross-Origin-Embedder-Policy: require-corp |
| Cross-Origin-Resource-Policy (CORP) | Controls which origins may load the resource. | Cross-Origin-Resource-Policy: same-site |
| Cache-Control | Defines caching behavior for sensitive data. | Use Cache-Control: no-store for highly sensitive responses and Cache-Control: private for user - specific data |
| Set-Cookie (security attributes) | Sends cookies; security attributes are critical. | Include Secure; HttpOnly; SameSite=Strict (or Lax where appropriate) |
| Expect-CT | Certificate Transparency reporting - browsers now recommend removal. | Do not send this header |
| Server / X-Powered-By / X-AspNet-Version | Reveal server software; not a security header but should be removed or set to a generic value. | Remove or replace with Server: hidden |
| X-Robots-Tag | Controls search - engine indexing of non - HTML resources. | X-Robots-Tag: noindex, nofollow for private content |
| X-DNS-Prefetch-Control | Disables DNS prefetching to reduce information leakage. | X-DNS-Prefetch-Control: off |
How to add the headers in common web servers
Apache (httpd.conf or .htaccess)
# HSTS
Header always set Strict-Transport-Security "max-age=63072000; includeSubDomains; preload"
# X-Frame-Options
Header always set X-Frame-Options "DENY"
# X-Content-Type-Options
Header always set X-Content-Type-Options "nosniff"
# Referrer-Policy
Header always set Referrer-Policy "strict-origin-when-cross-origin"
# Permissions-Policy (example)
Header always set Permissions-Policy "geolocation=(), camera=(), microphone=()"
# Remove server banner
ServerSignature Off
Header unset Server
Header unset X-Powered-By
Restart Apache after editing.
Nginx (nginx.conf or site - specific block)
add_header Strict-Transport-Security "max-age=63072000; includeSubDomains; preload" always;
add_header X-Frame-Options "DENY" always;
add_header X-Content-Type-Options "nosniff" always;
add_header Referrer-Policy "strict-origin-when-cross-origin" always;
add_header Permissions-Policy "geolocation=(), camera=(), microphone=()" always;
# Hide server version
server_tokens off;
Reload Nginx with nginx -s reload.
Express (Node.js) using helmet middleware
const helmet = require('helmet');
app.use(helmet({
hsts: { maxAge: 63072000, includeSubDomains: true, preload: true },
frameguard: { action: 'deny' },
xssFilter: false, // disable legacy filter
hidePoweredBy: true,
noSniff: true,
referrerPolicy: { policy: 'strict-origin-when-cross-origin' },
permissionsPolicy: { features: { geolocation: [], camera: [], microphone: [] } }
}));
// Set cookie security attributes
app.use((req, res, next) => {
res.cookie('session', token, { httpOnly: true, secure: true, sameSite: 'strict' });
next();
});
Helmet adds most headers automatically; you can customize each option as shown.
How to verify the headers are present
- Use a browser developer console: open the Network tab, reload the page, and inspect the response headers.
- Run a command - line curl request:
curl -I https://example.com | grep -i "strict-transport-security\|content-security-policy\|x-frame-options"
- Run Decloak’s free scan on the URL. The HTTP/TLS security posture layer will report missing or mis - configured headers and give a grade.
Common pitfalls and how to avoid them
- Setting HSTS on HTTP sites - HSTS only works over HTTPS; ensure the site redirects to HTTPS before adding the header.
- Overly permissive CSP - Start with
default-src 'self'and add sources only as needed; a broken CSP will break page functionality. - Conflicting headers - Some browsers treat
X-Frame-OptionsandContent-Security-Policy: frame-ancestorsas mutually exclusive; use only one mechanism. - Forgetting subdomains - Include
includeSubDomainsin HSTS and replicate the same header set on every subdomain. - Dynamic cookie attributes - If you set cookies in code, always include
Secure; HttpOnly; SameSiteattributes; otherwise the Set - Cookie header may be missing security flags.
When to use additional headers
- COOP and COEP are valuable for sites that embed cross - origin iframes or use SharedArrayBuffer. Add them when you need strong isolation between browsing contexts.
- CORP complements COEP for resources that cannot set
crossoriginattributes. - X-Robots-Tag is useful for API endpoints or private PDFs you do not want indexed.
Summary
OWASP provides a clear, vetted checklist of HTTP response headers that defend against a range of web - based attacks. Implementing the recommended values is a matter of a few configuration lines per server type, and you can verify the result instantly with curl or Decloak’s free scan. Regularly re - run the scan after any deployment change to keep your header set in sync with the live site.
Related guides
How to Fix a Missing Content - Security - Policy Header
Learn concrete steps to add, test, and harden a Content - Security - Policy header, from server configuration to iterative reporting and verification.
Is HTTP 1.1 a security risk?
HTTP 1.1 is not a direct vulnerability, but its plain - text design and parsing ambiguities can create attack surfaces that need mitigation, especially when not used over TLS.
Is JavaScript a security risk?
JavaScript can be a major attack surface because injected scripts run with the same privileges as the page, but proper sanitization, CSP, and safe frameworks eliminate most risks.