Skip to content
FlexibleToolsAI
Security Guide8 min read Updated September 28, 2026

How to Add HTTP Security Headers to Your Website

Six HTTP response headers block whole classes of attacks — cross-site scripting, clickjacking, protocol downgrades and data leaks — and most sites are missing several. Here's what each one does and copy-paste snippets for the most common servers and platforms.

Quick Takeaway

Add these response headers: Strict-Transport-Security: max-age=31536000; includeSubDomains, X-Content-Type-Options: nosniff, X-Frame-Options: DENY (or CSP frame-ancestors), Referrer-Policy: strict-origin-when-cross-origin, Permissions-Policy: camera=(), microphone=(), geolocation=(), and a Content-Security-Policy tested first in Report-Only mode. Set them in your web server (Nginx add_header, Apache Header set), CDN (Cloudflare Transform Rules) or framework, then re-scan to confirm.

The six headers and what they do

Strict-Transport-Security (HSTS) makes browsers use HTTPS for every future visit. X-Content-Type-Options: nosniff stops browsers guessing file types. X-Frame-Options (or CSP frame-ancestors) stops other sites framing yours for clickjacking. Referrer-Policy limits what URLs leak to other sites. Permissions-Policy turns off browser features you don't use. Content-Security-Policy restricts where scripts and other resources can load from — the strongest defence against XSS.

Check your current headers and grade with the Security Headers Checker.

Nginx

Inside your server block (HTTPS): add_header Strict-Transport-Security "max-age=31536000; includeSubDomains" always; add_header X-Content-Type-Options "nosniff" always; add_header X-Frame-Options "DENY" always; add_header Referrer-Policy "strict-origin-when-cross-origin" always; add_header Permissions-Policy "camera=(), microphone=(), geolocation=()" always; then run nginx -t and reload.

Note: add_header in a location block replaces headers from the server block, so repeat them there if you use add_header in locations.

Apache and .htaccess

Enable mod_headers, then in the virtual host or .htaccess: Header always set Strict-Transport-Security "max-age=31536000; includeSubDomains", Header always set X-Content-Type-Options "nosniff", Header always set X-Frame-Options "DENY", Header always set Referrer-Policy "strict-origin-when-cross-origin" and Header always set Permissions-Policy "camera=(), microphone=(), geolocation=()".

WordPress, Cloudflare and Next.js

WordPress: add the Apache lines to .htaccess, ask your host, or use a reputable security-headers plugin. Cloudflare: Rules → Transform Rules → Modify Response Header → set each header for all requests; HSTS is also under SSL/TLS → Edge Certificates.

Next.js: return the headers from async headers() in next.config.js for source "/(.*)". Express: use the Helmet middleware, which sets sensible defaults.

Adding a Content-Security-Policy without breaking your site

CSP is the header most likely to break things, because it blocks any script, style or embed you forget to allow. Build a policy with the CSP Header Generator, deploy it first as Content-Security-Policy-Report-Only, watch the browser console for violations, adjust, then switch to enforcing. Evaluate any policy for weaknesses with the CSP Evaluator.

Try Free Web Tools Mentioned in This Guide

Frequently Asked Questions

Do security headers affect SEO?↓

Not directly, but HTTPS with HSTS is part of a secure setup and a hacked site loses rankings fast. Headers don't slow your site down.

Is X-XSS-Protection still needed?↓

No — modern browsers removed the XSS auditor. Set it to 0 or remove it and rely on Content-Security-Policy.

Can HSTS lock me out?↓

If you enable HSTS and later lose HTTPS, visitors can't reach the site until the max-age expires. Make sure HTTPS works on every subdomain before adding includeSubDomains or preload.

Related Guides