Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Scan for outdated or missing drivers - takes under a minute3Repair Windows errors before they cause bigger problemsiTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
A content security policy (CSP) is a set of rules that a website sends to a browser to control what the page can load or execute. Usually delivered in the Content-Security-Policy HTTP response header, CSP helps limit the damage that malicious injected content—especially unauthorized scripts—can do.
How a content security policy works
The browser reads a page’s CSP and applies its directives while handling that page. Directives are separated by semicolons, and each one controls a resource type or security behavior. Source expressions such as 'self' and a hostname specify which sources a directive permits. CSP is therefore a set of browser-enforced rules for a protected page, not simply a general list of trusted programs.
For example, MDN gives this policy:
Content-Security-Policy: default-src 'self'; img-src 'self' example.com
Here, default-src 'self' acts as a fallback for fetch directives without their own rule. The separate img-src directive allows images from the site itself and example.com. The MDN CSP guide and header reference describe the policy syntax and behavior.
What CSP can protect against
CSP is commonly used to reduce the impact of content injection and cross-site scripting (XSS) by restricting where resources can come from and which scripts may run. It can also help address other risks and behaviors: frame-ancestors can restrict which pages embed a site, upgrade-insecure-requests can upgrade insecure requests, and Trusted Types requirements can constrain certain ways of handling potentially unsafe values. The W3C CSP Level 3 specification and MDN’s guide describe these uses.
#1 Best Overall
How CSP is delivered
HTTP response header
The usual delivery method is the Content-Security-Policy HTTP response header. A server can send the policy with the page so the browser can enforce it.
Meta element
A page can also use a <meta http-equiv="Content-Security-Policy"> element for some CSP uses. MDN notes that this method does not support every CSP feature, so it is not a full substitute for the response header. Multiple policies can apply to a resource; adding another policy can only further restrict its capabilities, not loosen restrictions already in force.
What CSP does not replace
CSP is defense in depth, not a cure for vulnerable application code. The W3C specification says, “CSP is not intended as a first line of defense against content injection vulnerabilities.” Input validation, output encoding, and sanitization are still necessary; CSP can reduce the harm when those defenses fail, but it does not make unsafe handling safe.
For script and plugin sources, the W3C specification recommends regulating them with script-src and object-src, or using default-src. A policy must also fit the site: legitimate dependencies and inline code may need changes, and a permissive rule can undermine the protection CSP is meant to provide.
How to introduce a policy safely
MDN recommends testing a policy before enforcing it. Start with the Content-Security-Policy-Report-Only header, review the reported violations, and adjust the policy to account for legitimate resources and code. Once the policy has been tested against the site’s behavior, deploy it in enforcement mode. MDN’s CSP implementation guide discusses this approach and strict policies based on script or style nonces and hashes.
There is no universal CSP that can be copied safely onto every website: the appropriate directives and sources depend on what the site needs to load and execute. CSP syntax, reporting capabilities, and browser behavior can evolve; the W3C page identifies a CSP Level 3 Working Draft dated September 16, 2026, and links to the latest published version.
Quick Recap
Best Value
- Comes with secure packaging
- It can be a gift item
- Easy to read text
Rank #4
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
Free tools Windows power users keep installed
One-click scans. No signup required.

