Back to Guides
Guide5 October 2026 · Updated 6 October 2026

Which HTTP security headers does OWASP recommend and how to implement them?

Decloak is an AI-powered web security intelligence platform that scans a site's HTTP/TLS posture, JavaScript, and third-party scripts to produce a report anyone can read. This guide is part of Decloak's library of practical, source-backed security guidance.

In this guide
  1. Key takeaways
  2. What are the OWASP - recommended HTTP security headers?
  3. How to add the headers in common web servers
  4. How to verify the headers are present
  5. Common pitfalls and how to avoid them
  6. When to use additional headers
  7. Summary

Key takeaways

The OWASP Secure Headers project defines a concrete list of response headers that browsers should see to improve security. Each header has a purpose and a recommended configuration value.

HeaderPurposeRecommended value
Strict-Transport-Security (HSTS)Forces browsers to use HTTPS only.Strict-Transport-Security: max-age=63072000; includeSubDomains; preload
Content-Security-Policy (CSP)Restricts the sources from which content can be loaded, mitigating XSS and data - injection attacks.Build a restrictive policy that matches your app; a minimal example is Content-Security-Policy: default-src 'self'; script-src 'self'
X-Frame-OptionsPrevents click - jacking by controlling framing.X-Frame-Options: DENY (or SAMEORIGIN if framing by your own domain is required)
X-Content-Type-OptionsStops MIME - type sniffing.X-Content-Type-Options: nosniff
Referrer-PolicyControls how much referrer information is sent.Referrer-Policy: strict-origin-when-cross-origin
X-XSS-ProtectionLegacy XSS filter; modern browsers ignore it, so disable to avoid false sense of security.X-XSS-Protection: 0
Permissions-PolicyLimits use of browser features such as camera or geolocation.Permissions-Policy: geolocation=(), camera=(), microphone=()
Cross-Origin-Opener-Policy (COOP)Isolates browsing context groups to prevent side - channel attacks.Cross-Origin-Opener-Policy: same-origin
Cross-Origin-Embedder-Policy (COEP)Requires cross - origin resources to grant permission.Cross-Origin-Embedder-Policy: require-corp
Cross-Origin-Resource-Policy (CORP)Controls which origins may load the resource.Cross-Origin-Resource-Policy: same-site
Cache-ControlDefines caching behavior for sensitive data.Use Cache-Control: no-store for highly sensitive responses and Cache-Control: private for user - specific data
Set-Cookie (security attributes)Sends cookies; security attributes are critical.Include Secure; HttpOnly; SameSite=Strict (or Lax where appropriate)
Expect-CTCertificate Transparency reporting - browsers now recommend removal.Do not send this header
Server / X-Powered-By / X-AspNet-VersionReveal server software; not a security header but should be removed or set to a generic value.Remove or replace with Server: hidden
X-Robots-TagControls search - engine indexing of non - HTML resources.X-Robots-Tag: noindex, nofollow for private content
X-DNS-Prefetch-ControlDisables DNS prefetching to reduce information leakage.X-DNS-Prefetch-Control: off

How to add the headers in common web servers

Apache (httpd.conf or .htaccess)

# HSTS
Header always set Strict-Transport-Security "max-age=63072000; includeSubDomains; preload"
# X-Frame-Options
Header always set X-Frame-Options "DENY"
# X-Content-Type-Options
Header always set X-Content-Type-Options "nosniff"
# Referrer-Policy
Header always set Referrer-Policy "strict-origin-when-cross-origin"
# Permissions-Policy (example)
Header always set Permissions-Policy "geolocation=(), camera=(), microphone=()"
# Remove server banner
ServerSignature Off
Header unset Server
Header unset X-Powered-By

Restart Apache after editing.

Nginx (nginx.conf or site - specific block)

add_header Strict-Transport-Security "max-age=63072000; includeSubDomains; preload" always;
add_header X-Frame-Options "DENY" always;
add_header X-Content-Type-Options "nosniff" always;
add_header Referrer-Policy "strict-origin-when-cross-origin" always;
add_header Permissions-Policy "geolocation=(), camera=(), microphone=()" always;
# Hide server version
server_tokens off;

Reload Nginx with nginx -s reload.

Express (Node.js) using helmet middleware

const helmet = require('helmet');
app.use(helmet({
 hsts: { maxAge: 63072000, includeSubDomains: true, preload: true },
 frameguard: { action: 'deny' },
 xssFilter: false, // disable legacy filter
 hidePoweredBy: true,
 noSniff: true,
 referrerPolicy: { policy: 'strict-origin-when-cross-origin' },
 permissionsPolicy: { features: { geolocation: [], camera: [], microphone: [] } }
}));
// Set cookie security attributes
app.use((req, res, next) => {
 res.cookie('session', token, { httpOnly: true, secure: true, sameSite: 'strict' });
 next();
});

Helmet adds most headers automatically; you can customize each option as shown.

How to verify the headers are present

  1. Use a browser developer console: open the Network tab, reload the page, and inspect the response headers.
  2. Run a command - line curl request:
curl -I https://example.com | grep -i "strict-transport-security\|content-security-policy\|x-frame-options"
  1. Run Decloak’s free scan on the URL. The HTTP/TLS security posture layer will report missing or mis - configured headers and give a grade.

Common pitfalls and how to avoid them

When to use additional headers

Summary

OWASP provides a clear, vetted checklist of HTTP response headers that defend against a range of web - based attacks. Implementing the recommended values is a matter of a few configuration lines per server type, and you can verify the result instantly with curl or Decloak’s free scan. Regularly re - run the scan after any deployment change to keep your header set in sync with the live site.

Free security scan

See what's actually exposed on your site.

Decloak's free scan runs in about 15 seconds, no account required, and covers:

  • HTTP/TLS security posture
  • JavaScript CVEs
  • Exposed Supabase/Lovable/Base44 misconfigurations
  • AI-written executive summary