Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

A content security policy (CSP) is a set of rules that a website sends to a browser to control what the page can load or execute. Usually delivered in the Content-Security-Policy HTTP response header, CSP helps limit the damage that malicious injected content—especially unauthorized scripts—can do.

How a content security policy works

The browser reads a page’s CSP and applies its directives while handling that page. Directives are separated by semicolons, and each one controls a resource type or security behavior. Source expressions such as 'self' and a hostname specify which sources a directive permits. CSP is therefore a set of browser-enforced rules for a protected page, not simply a general list of trusted programs.

For example, MDN gives this policy:

Content-Security-Policy: default-src 'self'; img-src 'self' example.com

Here, default-src 'self' acts as a fallback for fetch directives without their own rule. The separate img-src directive allows images from the site itself and example.com. The MDN CSP guide and header reference describe the policy syntax and behavior.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What CSP can protect against

CSP is commonly used to reduce the impact of content injection and cross-site scripting (XSS) by restricting where resources can come from and which scripts may run. It can also help address other risks and behaviors: frame-ancestors can restrict which pages embed a site, upgrade-insecure-requests can upgrade insecure requests, and Trusted Types requirements can constrain certain ways of handling potentially unsafe values. The W3C CSP Level 3 specification and MDN’s guide describe these uses.

How CSP is delivered

HTTP response header

The usual delivery method is the Content-Security-Policy HTTP response header. A server can send the policy with the page so the browser can enforce it.

Meta element

A page can also use a <meta http-equiv="Content-Security-Policy"> element for some CSP uses. MDN notes that this method does not support every CSP feature, so it is not a full substitute for the response header. Multiple policies can apply to a resource; adding another policy can only further restrict its capabilities, not loosen restrictions already in force.

What CSP does not replace

CSP is defense in depth, not a cure for vulnerable application code. The W3C specification says, “CSP is not intended as a first line of defense against content injection vulnerabilities.” Input validation, output encoding, and sanitization are still necessary; CSP can reduce the harm when those defenses fail, but it does not make unsafe handling safe.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

For script and plugin sources, the W3C specification recommends regulating them with script-src and object-src, or using default-src. A policy must also fit the site: legitimate dependencies and inline code may need changes, and a permissive rule can undermine the protection CSP is meant to provide.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How to introduce a policy safely

MDN recommends testing a policy before enforcing it. Start with the Content-Security-Policy-Report-Only header, review the reported violations, and adjust the policy to account for legitimate resources and code. Once the policy has been tested against the site’s behavior, deploy it in enforcement mode. MDN’s CSP implementation guide discusses this approach and strict policies based on script or style nonces and hashes.

There is no universal CSP that can be copied safely onto every website: the appropriate directives and sources depend on what the site needs to load and execute. CSP syntax, reporting capabilities, and browser behavior can evolve; the W3C page identifies a CSP Level 3 Working Draft dated September 16, 2026, and links to the latest published version.

Quick Recap

Best Value
Sale
The Web Application Hacker's Handbook: Finding and Exploiting Security Flaws
  • Comes with secure packaging
  • It can be a gift item
  • Easy to read text

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.