Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The safest way to implement security HTTP headers is to define one policy at the component that reliably serves your responses—application, web server, reverse proxy, CDN, or gateway—then verify that policy on successful pages, redirects, errors, APIs, static files, and authenticated responses. Start with low-risk headers, deploy Content-Security-Policy (CSP) in report-only mode, fix legitimate violations, and only then enforce it. Headers reduce browser-side risk, but they do not replace TLS, output encoding, sanitization, authentication, authorization, or dependency management.

What each security header protects

Header Primary protection Important implementation detail
Strict-Transport-Security (HSTS) Transport downgrade and accidental HTTP use Browsers remember to use HTTPS. Add includeSubDomains only after every covered subdomain is HTTPS-ready.
Content-Security-Policy (CSP) Restricts scripts, styles, images, frames, connections and other resource behavior; can stop unauthorized framing Build it from this application’s real dependencies. Roll out with report-only first.
X-Content-Type-Options: nosniff MIME-type confusion Send an accurate Content-Type for every resource; nosniff tells browsers not to guess.
Referrer-Policy Referrer-path and query-string leakage strict-origin-when-cross-origin is a practical default when same-origin detail is useful.
Permissions-Policy Unneeded browser capabilities such as camera, microphone or geolocation Disable features by default and explicitly allow only required origins or frames.
Content-Security-Policy: frame-ancestors Clickjacking Use 'none' when framing is never valid, or list exact trusted origins.
X-Frame-Options Legacy clickjacking compatibility DENY remains useful as defense in depth, but CSP frame-ancestors is the modern control.

Do not add the obsolete X-XSS-Protection header as a “quick win.” Legacy filtering can introduce vulnerabilities; CSP and secure coding are safer controls.

1. Inventory where responses are produced

Before editing configuration, trace a request from the public URL to the component that emits the response. It may be application middleware, a web server, reverse proxy, CDN, API gateway, or a combination. Choose one documented policy owner for each header so layers do not overwrite one another with conflicting values.

  • Check whether HTTP-to-HTTPS redirects receive the same intended headers.
  • Check custom 4xx/5xx pages, framework-generated errors and authentication redirects.
  • Check API and file-download routes, not only HTML pages.
  • Check whether CDN caching can serve an older header value after deployment.

Some stacks attach headers only after the application handler succeeds. Configure the proxy or server as well when it must cover failures and redirects.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
FortiGate-40F Firewall Appliance - 5 Gigabit Ethernet RJ45 Ports, Ideal for Small Businesses (Appliance Only, No Subscription) (FG-40F)
  • Compact and Efficient Design: The FortiGate 40F is designed for small to mid-sized businesses and enterprise branch offices, featuring a compact, fanless desktop form factor that ensures quiet operation and minimizes space usage.
  • Robust Connectivity Options: Equipped with 5 GE RJ45 ports, including 1 WAN port and 4 internal ports, this model provides essential connectivity and flexibility for various network configurations in a small-scale environment.
  • High-Performance Security: Offers up to 1 Gbps IPS throughput and 600 Mbps threat protection throughput, using Fortinet’s purpose-built security processor technology to deliver industry-leading performance and protection for SSL encrypted traffic.
  • Advanced Threat Protection: Integrated with Fortinet’s AI-powered FortiGuard Labs, the FortiGate 40F offers comprehensive cybersecurity, identifying and mitigating both known and unknown threats to maintain robust security across your network.
  • Simplified Management and Deployment: Features a user-friendly management console that provides comprehensive network automation and visibility, coupled with Zero Touch Integration with Fortinet’s Security Fabric for easy deployment.

2. Deploy a conservative baseline

Adapt this starting set to your application. The CSP and Permissions-Policy values are deliberately restrictive; add only origins and features you actually need.

Strict-Transport-Security: max-age=31536000
X-Content-Type-Options: nosniff
Referrer-Policy: strict-origin-when-cross-origin
Permissions-Policy: geolocation=(), camera=(), microphone=()
Content-Security-Policy: default-src 'self'; object-src 'none'; base-uri 'self'; frame-ancestors 'none'

HSTS without locking out subdomains

max-age=31536000 tells a supporting browser to prefer HTTPS for one year after it receives the header over HTTPS. Add includeSubDomains only when every covered hostname has working HTTPS, valid certificates and an HTTP-to-HTTPS path. Treat HSTS preload as a separate operational commitment: confirm certificate renewal, redirects, subdomain inventory and recovery procedures before requesting it.

Correct MIME declarations and nosniff

Return the right Content-Type for HTML, JavaScript, CSS, images, fonts, JSON and downloads. Then send X-Content-Type-Options: nosniff. A wrong MIME declaration can cause a legitimate resource to stop working once guessing is disabled; fix the declaration rather than removing nosniff.

Referrer and feature controls

strict-origin-when-cross-origin preserves useful same-origin referrer detail while sending only an origin to another site. If URLs can contain secrets, avoid placing those secrets in paths or query strings and choose a stricter policy. In Permissions-Policy, review geolocation, camera, microphone, fullscreen, payment and other capabilities against actual product requirements. An empty allowlist such as camera=() disables that feature for the page and its frames.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

3. Build and roll out CSP safely

Start in report-only mode

Deploy this header first:

Content-Security-Policy-Report-Only: default-src 'self'; object-src 'none'; base-uri 'self'; frame-ancestors 'none'

Collect violation reports in your browser tooling or reporting pipeline. Classify each report: legitimate script, style, image, font, worker, frame or connection; an unnecessary dependency; or an actual policy violation. Remove unnecessary third-party code where possible. Add narrowly scoped origins for dependencies that remain, then test again.

Move to enforcement

When legitimate traffic is covered, replace Content-Security-Policy-Report-Only with Content-Security-Policy. Avoid broad wildcards and resist using unsafe-inline as a shortcut. Prefer external files, nonces or hashes appropriate to your framework, and keep directives as narrow as the application allows.

CSP limits what the browser can load or execute; it is not a substitute for contextual output encoding, input handling, sanitization, safe templates or patched dependencies. A server-side injection flaw still needs a code fix.

Rank #2
FortiGate-60F Network Security Appliance Plus 1 Year FortiGuard Unified Threat Protection (UTP) and FortiCare Premium (FG-60F-BDL-950-12)
  • HARDWARE PLUS SECURITY SERVICES: FortiGate-60F Firewall Appliance bundled with 1 year of FortiCare Premium and FortiGuard Unified Threat Protection.
  • UNIFIED THREAT PROTECTION (UTP): Secures against advanced online threats with comprehensive web filtering and anti-botnet technologies.
  • OPTIMIZED FOR MEDIUM-SIZED BUSINESSES: Tailored for businesses needing robust security without the infrastructure of larger enterprises.
  • RELIABLE CUSTOMER SUPPORT: FortiCare Premium ensures high-quality support and service continuity.
  • EFFECTIVE PROTECTION: Employs advanced filtering technologies to safeguard against sophisticated threats.

4. Control clickjacking and framing

If no page may be embedded, use:

Content-Security-Policy: ...; frame-ancestors 'none'
X-Frame-Options: DENY

If a partner integration requires framing, replace 'none' with the exact trusted origins in frame-ancestors. Keep X-Frame-Options when older-browser compatibility or defense in depth matters, but do not treat it as a complete replacement for CSP framing policy. Test the policy from an unauthorized origin and from every approved integration.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

5. Configure headers in common delivery layers

Application middleware

Set headers on the common response path, before route-specific handlers return. Ensure the middleware also runs for framework errors, redirects and API responses. If a framework has separate static-file handling, configure that path explicitly.

Web server, reverse proxy or CDN

Edge configuration is useful for coverage across applications, but confirm it does not overwrite an application-specific CSP. Decide whether the edge or origin owns each value, purge cached responses after changes, and verify that error and redirect responses pass through the same rules.

Multiple applications and subdomains

Keep a written inventory of hostnames and policies. A header intended for one application can break another when applied globally—for example, a CSP that omits a payment provider or an HSTS subdomain that is not yet HTTPS-ready.

6. Test every response class

Use a representative URL matrix rather than checking one homepage:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • 200 HTML page and a page with authenticated content.
  • HTTP redirect and HTTPS redirect.
  • 404 and 500 responses.
  • JSON API response, file download and each static asset type.
  • Pages containing third-party scripts, fonts, frames, workers and network calls.

For each response, confirm every intended header is present, non-empty and has the expected value. An empty security header may be ignored by the browser. Also verify that the Content-Type matches the body, that CSP reports contain no unclassified legitimate dependency, and that cached responses are current.

Command-line checks

curl -sS -D - -o /dev/null https://example.com/
curl -sS -D - -o /dev/null -L https://example.com/redirect
curl -sS -D - -o /dev/null https://example.com/api/resource

Inspect the response headers in each command’s output. In browser developer tools, reload with the Network panel open, select the document and assets, and review the Console for CSP violations. Attempt to load the page in an unauthorized iframe to verify framing protection.

Rank #3
GL.iNet GL-MT5000 Brume 3 Wired VPN Security Gateway NO Wi-Fi
  • 【Up to 1100 Mbps VPN Speed 】 Hardware-accelerated WireGuard and OpenVPN-DCO deliver up to 1100 Mbps VPN throughput, over 3× faster than Brume 2 for smooth remote access and file transfers.
  • 【Three 2.5G Ports & Multi-WAN】Tri-port 2.5GbE design with flexible WAN LAN configuration supports multi-gigabit wired setups, dual-ISP Multi-WAN and failover to keep home and SOHO networks online.
  • 【Stealth VPN Obfuscation】VPN obfuscation disguises VPN traffic as regular HTTPS, helping you evade blocking, bypass restrictive networks and maintain stable, private connections.
  • 【DPI protection】Deep Packet Inspection with visual dashboards blocks adult/gambling/malicious sites, while SQM and QoS prioritize gaming, calls, and video when bandwidth is tight
  • 【OpenWrt & USB 3.0 Expansion】OpenWrt with 1GB DDR4 and 8GB eMMC lets you install plugins and build VPN, ad-blocking or NAS, while USB 3.0 Type‑C connects high-speed storage or 4G/5G dongles

Functional checks

  • Confirm required scripts, styles, images, fonts, workers, frames and connections still load after CSP enforcement.
  • Confirm disabled camera, microphone and geolocation calls fail unless explicitly allowed.
  • Follow links to less-trusted origins and verify that sensitive paths or query strings are not leaked in the referrer.
  • Raise HSTS max-age only after certificate, redirect and subdomain behavior is stable.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

7. Troubleshoot common failures

“The header appears on the homepage but not on errors.”

Cause: error handling or a proxy-generated response bypasses application middleware. Fix: configure the component that emits the error, or move the baseline headers to a layer covering both normal and error responses. Recheck 3xx, 4xx and 5xx responses.

“The page breaks after enabling CSP.”

Cause: a missing script, style, font, frame, worker, image or connection origin. Fix: return to report-only mode, classify each violation, remove needless dependencies, then add only the required exact origins or safer nonces/hashes. Do not solve every report with a wildcard.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

“A script or stylesheet is blocked despite the right origin.”

Cause: inline code, an unexpected redirect, a different asset host, or a directive such as script-src overriding default-src. Fix: inspect the blocked URL and effective directive in the Console, then update the specific directive or refactor the inline code.

“An asset stops loading after nosniff.”

Cause: the server advertises the wrong MIME type. Fix: correct Content-Type at the origin or edge; keep nosniff enabled.

“A legitimate partner cannot embed the page.”

Cause: frame-ancestors 'none', an incomplete origin list, or a conflicting X-Frame-Options: DENY. Fix: document the approved origins and update both controls consistently. Do not allow arbitrary framing.

“HSTS causes an unreachable subdomain.”

Cause: includeSubDomains covered a host without working HTTPS. Fix: restore HTTPS and certificate coverage, or do not include that subdomain until it is ready. Plan HSTS scope before increasing max-age.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Performance, reliability and ownership

Headers are small and normally inexpensive; the operational risk is policy breakage and inconsistent coverage. Centralize policy ownership, version changes, monitor CSP reports, and roll out high-impact changes gradually. Keep third-party dependencies to the minimum needed, because every new origin increases CSP review and availability surface. Cache purges and configuration propagation should be part of the deployment plan.

Rank #4
Ubiquiti Cloud Gateway Ultra (UCG-Ultra)
  • Runs UniFi Network for full-stack network management
  • Manages 30+ UniFi Network devices and 300+ clients
  • 1 Gbps routing with IDS/IPS
  • Multi-WAN load balancing
  • 0.96" LCM status display

These controls defend the browser boundary. They cannot correct an insecure authorization decision, missing authentication, unsanitized output, vulnerable library or misconfigured TLS certificate. Continue secure coding, dependency updates, access-control testing and TLS maintenance.

Or skip the browser setup

To visually inspect a deployed page after changing headers, ScreenshotNeo can capture it with one request. Its cleanup steps accept cookie or consent banners and remove more than 60 known consent platforms, newsletter popups and chat widgets before capture; each step can be turned off. Bot checks or CAPTCHAs, blank pages, timeouts, failed loads and cache hits are not billed, and the response identifies the page verdict and billing status in X-Page-Verdict and X-Billed headers. It also provides an MCP server for AI agents such as Claude and Cursor, with take_screenshot, get_page_info and capture_pdf.

Example request (see the ScreenshotNeo API documentation):

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://example.com -o shot.webp

The Free plan includes 1,000 screenshots per month with no card. Paid plans start at $5 for 3,000 screenshots; every feature is included on every plan. Create a free ScreenshotNeo account to try it.

FAQ

Should security headers be set on API responses?

Yes. Test APIs, redirects, errors, static files and authenticated responses, then apply only policies meaningful for each response type.

Is CSP enough to prevent XSS?

No. CSP is a browser-enforced layer; output encoding, sanitization, safe templating and dependency security remain necessary.

When can I add HSTS includeSubDomains?

Only after every covered subdomain is HTTPS-ready, with valid certificates, redirects and a recovery plan.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.