Infrastructure

HTTP security headers

Short definition

HTTP security headers are small server instructions sent to the browser that pre-empt specific types of attack.

As a page loads, the server sends a set of invisible headers alongside the content. HTTP security headers are the subset of those that tell the browser what not to allow on that page.

Content-Security-Policy blocks malicious scripts from running, Strict-Transport-Security stops connections from downgrading to an unencrypted one, X-Frame-Options stops the site being quietly embedded inside another page. Each header locks a different kind of attack.

An SSL certificate encrypts the data, but without these headers other doors stay open through browser behaviour, the two complement each other, neither replaces the other.

Which security headers a page actually sends can be checked without touching any code by opening the browser's developer tools, switching to the Network tab, and inspecting the response headers on any request. It is a fast, non-technical way to verify configuration, if a given header never shows up there, it simply has not been set on the server.

Why it matters

Missing security headers give attackers room to inject code or impersonate the site, and this usually goes unnoticed for months. Properly configured headers close those doors with no added server cost.

Illustrative example

A payment provider's security audit found the Content-Security-Policy header had never been set, adding it took an hour and changed the whole audit result.

Related terms

Related article

If you don’t know where to start, that’s fine; you’re in the right place.

Your project might already be clear in your head, or still just an idea. Either works. On a short call we talk through where you are and where you could go, together.

Let’s set up a call
Let’s talk about your project