The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
HTTP security headers tell browsers how to handle your site’s content, connections, embeds, and browser features. Six useful controls are Content-Security-Policy (CSP), Strict-Transport-Security (HSTS), X-Content-Type-Options, X-Frame-Options, Referrer-Policy, and Permissions-Policy. They address different behaviors, so one does not replace the others. Add them at the response layer used by your server, application, hosting platform, CDN, or reverse proxy, then verify real responses and site behavior.
What each header controls
| Header | Browser behavior it controls | What to check before rollout |
|---|---|---|
| Content-Security-Policy | Which resources a page may load and which sites may embed it. | Scripts, styles, images, fonts, APIs, frames, and other required resources. |
| Strict-Transport-Security | Instructs browsers to use HTTPS instead of HTTP for the site. | HTTPS readiness across the scope you intend to cover. |
| X-Content-Type-Options | Prevents browsers from inferring a different MIME type for certain resources. | Correct Content-Type values for served files. |
| X-Frame-Options | Controls whether a document can be rendered in a frame. | Whether the site has legitimate framing or embedding needs. |
| Referrer-Policy | Controls how much referrer information accompanies requests. | Whether application flows rely on referrer details. |
| Permissions-Policy | Controls selected browser features for a document and embedded frames. | Which features the site and its embeds actually use, and browser support. |
1. Content-Security-Policy: restrict what the page can load
Content-Security-Policy (CSP) sets rules for resources a browser may load, helping limit the impact of some cross-site scripting attacks. Its directives govern different behaviors: default-src provides a fallback for fetch directives, script-src controls script sources, base-uri restricts URLs usable by a document’s <base> element, and frame-ancestors determines which parents may embed the page. See MDN’s CSP documentation.
Build and test a policy
- Inventory the scripts, stylesheets, images, fonts, API connections, and frames your pages actually use.
- Define directives that permit those resources while restricting unneeded sources. CSP is site-specific; an overly restrictive policy can break page features.
- Where practical, start with
Content-Security-Policy-Report-Onlyto observe violations before enforcing the policy. - Review the observed violations, adjust the policy for legitimate resources, and test key pages and integrations before switching to enforcement.
This is a discussion example, not a universal policy:
Content-Security-Policy: default-src 'self'; object-src 'none'; base-uri 'self'; frame-ancestors 'self'
A real site may need different rules for scripts, styles, APIs, embedded content, and nonce or hash strategies. This example alone does not establish that a policy is suitable for a particular site.
#1 Best Overall
2. Strict-Transport-Security: tell browsers to use HTTPS
Strict-Transport-Security (HSTS) tells browsers to use HTTPS instead of HTTP for the site. Serve it only after HTTPS is correctly configured for the domain and any intended subdomains. Decide deliberately whether to cover subdomains or pursue preload; those choices expand the policy’s scope and should not be copied without checking readiness. The available reference establishes HSTS’s function but does not establish a recommended max-age, subdomain scope, or preload configuration. See MDN’s HSTS overview.
3. X-Content-Type-Options: prevent MIME-type guessing
Set X-Content-Type-Options: nosniff so browsers respect the MIME type declared in the response’s Content-Type rather than inferring a different one. In particular, browsers can block script and stylesheet requests served with unexpected MIME types. The header does not correct a wrong MIME type, so check both the header and the file’s declared type. See MDN’s X-Content-Type-Options reference.
Rank #2
4. X-Frame-Options: control who can frame a page
X-Frame-Options controls whether a document can be rendered in a frame, iframe, embed, or object. It can help defend against unwanted embedding such as clickjacking. Choose DENY if the page should never be framed, or SAMEORIGIN if framing by pages from the same origin is needed. Preserve legitimate integrations and check them after rollout. For more comprehensive and flexible control, MDN points to CSP’s frame-ancestors directive. See MDN’s X-Frame-Options documentation.
Recommended Free Tools
5. Referrer-Policy: limit URL details sent with requests
Referrer-Policy determines how much referrer information is included with requests. MDN documents strict-origin-when-cross-origin as the default when no policy is set or the value is invalid: same-origin requests retain the URL, cross-origin secure requests receive only the origin, and less-secure destinations do not receive the referrer. Setting the intended policy explicitly makes that choice clear. Avoid unsafe-url unless sending the full source URL is intended, since paths or query details may be private. Check whether any application flow relies on referrer details before changing the policy. See MDN’s Referrer-Policy reference.
Rank #3
- 【Tired of constantly searching for or resetting your passwords?】 MOSA BEAR password keeper book is the perfect solution for you! This password book provides a dedicated place to securely store all your important website addresses, emails, usernames and passwords, ensuring your information is protected and easy to find. The well-designed log pages help you manage multiple accounts in a systematic way, saying goodbye to password confusion.
- 【Premium Design & Password Security】 The password book with alphabetical tabs features an anonymous cover design with no title on the cover, effectively avoiding information exposure. The password keeper design is specifically designed with password security in mind, providing space to record password hints instead of writing directly on the password itself, further protecting your important information.
- 【Simple Layout and Plenty of Space】The 160-page password logbook is designed to provide ample space to record passwords and other important information. It can store up to 414 passwords. In addition, it provides extra pages to record other information, such as email setup, card information, computer operating system information, software licenses, and more. The journal also includes 3 blank pages at the end for you to add additional notes.
- 【Palm-sized Size & Premium Quality】 This password notebook has an ideal size, 4.3" x 5.7", for carrying around, whether in a purse or pocket. Its sturdy glue binding allows the notebook to unfold smoothly and is more comfortable to use. The inner pages are made of high-quality 100GSM thick paper, which can effectively reduce ink penetration and ensure a cleaner and neater writing effect. The overall design takes into account both portability and durability, making it an ideal choice for recording important passwords.
- 【A-Z Tabs for Quick Search 】Our password book comes with alphabetical tabs to help you find the password you need quickly and easily. Alphabetically organized tabs ensure that you can quickly flip to the right section, saving you the time and hassle of searching for your password.
6. Permissions-Policy: limit selected browser features
Permissions-Policy lets a site allow or deny selected browser features in its document and embedded frames. For example, geolocation=() denies geolocation. Feature allowlists and iframe rules affect whether embedded content can use a feature, so align the policy with the features the site and its embeds genuinely need. MDN marks this header as having limited availability; check current browser support before relying on it in production. See MDN’s Permissions-Policy documentation.
How to add and verify the headers
The exact configuration path depends on your web stack. Set the headers where your site’s HTTP responses are generated or modified—such as the web server, application, hosting platform, CDN, or reverse proxy—and avoid assuming that a setting on one layer appears on every response.
Quick Recap
Best Value
Rank #4
- Bookbound planner helps you keep track of passwords and favorite websites
- Room for over 200 entries; 3.5 x 6 inch page sizes
- User name and security questions field
- Tips for what makes a strong password; web resources; notes pages
- Printed on quality paper containing 30% post-consumer waste; black simulated leather cover; 3.63 x 6.13 x .21 inches
- Choose the response layer that serves or modifies headers for the pages and resources you want to protect.
- Configure each header for its intended scope. For CSP, use a site-specific policy and consider report-only observation before enforcement. For HSTS, confirm HTTPS readiness before extending coverage. For framing, retain any legitimate embedding behavior.
- Inspect actual HTTP responses, including redirects and important page and resource types, to confirm that the expected headers are present where intended.
- Check JavaScript, CSS, and other served files for accurate
Content-Typevalues alongsidenosniff. - Exercise key pages, scripts, embedded content, and application flows after policy changes. Check current browser support before depending on Permissions-Policy.
- Repeat the checks after changes to hosting, a CDN, reverse proxy, application framework, or third-party integrations.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

