Security headers are a few lines of configuration that tell the browser how to treat your site: always use HTTPS, never let another site frame your pages, never guess a file's type, and run only the scripts you allow. They cost nothing and take minutes to add. This guide explains the headers that matter in 2026, the values to start with, and how to set them on Apache (including Domain India shared hosting), nginx and Node.js.
Start with four headers that rarely break anything: Strict-Transport-Security, X-Content-Type-Options: nosniff, Referrer-Policy and a framing rule (frame-ancestors in CSP, or X-Frame-Options). Then add a Content-Security-Policy in report-only mode, fix what it reports, and enforce it. On Domain India cPanel and DirectAdmin hosting, you set them in .htaccess with Header always set.
1. Why headers matter
Every HTTP response carries headers as well as content. A handful of them are instructions to the browser. Used well, they block whole classes of attack, such as HTTPS downgrades on public Wi-Fi, clickjacking, MIME sniffing and many cross-site scripting (XSS) injections, without changing your application code.
They are a second line of defence, not a replacement for secure code. Escape output, validate input and keep your CMS and plugins updated first; headers catch what slips through.
2. The headers at a glance
| Header | Protects against | Starting value | Risk of breaking the site |
|---|---|---|---|
| Strict-Transport-Security | HTTPS downgrade and cookie theft over HTTP | max-age=300 at first, then a year | Low, once every page works over HTTPS |
| X-Content-Type-Options | Browsers running an upload as script | nosniff | Very low |
| Referrer-Policy | Leaking full URLs to other sites | strict-origin-when-cross-origin | Very low |
Framing (frame-ancestors, X-Frame-Options) | Clickjacking | 'self' / SAMEORIGIN | Low, unless another site embeds yours |
| Permissions-Policy | Misuse of camera, microphone, location | Disable what you don't use | Low |
| Content-Security-Policy | XSS and injected scripts | Report-only first | High until tuned |
| Cross-Origin-Opener-Policy | Cross-window attacks | same-origin | Medium: can break login pop-ups |
3. Strict-Transport-Security (HSTS)
HSTS tells the browser to use HTTPS for your site from now on, even if someone types http://.
Strict-Transport-Security: max-age=31536000; includeSubDomainsmax-ageis how long, in seconds, the browser remembers the rule. One year is typical.includeSubDomainscovers every subdomain. Add it only when all your subdomains, includingwebmailor old test sites, have valid HTTPS.preloadasks browsers to ship your domain with HTTPS built in (submitted at hstspreload.org). It is slow to undo, so add it last, if at all.
Browsers remember HSTS for the whole max-age, and you cannot take it back early. Begin with max-age=300 (five minutes), check every page and subdomain over HTTPS, then raise it step by step to a year. Make sure your SSL certificate renews automatically before you commit.
4. X-Content-Type-Options, Referrer-Policy and framing
These three are safe on almost any site.
X-Content-Type-Options: nosniff
Referrer-Policy: strict-origin-when-cross-origin
X-Frame-Options: SAMEORIGIN- nosniff stops the browser guessing a file's type, so an uploaded "image" can't be run as a script.
- strict-origin-when-cross-origin sends the full URL within your own site, only your domain name to other HTTPS sites, and nothing when a link leads from HTTPS to HTTP. It is already the browser default, but setting it makes your intent explicit.
- Framing: the modern control is
frame-ancestorsinside your CSP, for exampleframe-ancestors 'self'.X-Frame-Optionsis the older header; keep it for older browsers, with the same meaning. UseDENYif nobody, including you, needs to frame the page.
X-XSS-Protection is obsolete. Modern browsers ignore it, so leave it out or set it to 0.
5. Permissions-Policy
Turn off browser features your site never uses, so injected code cannot use them either:
Permissions-Policy: camera=(), microphone=(), geolocation=(), payment=()Empty brackets mean "no one". To allow a feature on your own pages only, write geolocation=(self).
6. Content-Security-Policy (CSP)
CSP lists where scripts, styles, images, fonts and connections may come from. A strict policy stops most injected scripts from running. It is also the header most likely to break your site, because analytics tags, chat widgets and inline scripts all need to be allowed.
A reasonable starting policy:
Content-Security-Policy: default-src 'self'; script-src 'self'; style-src 'self' 'unsafe-inline'; img-src 'self' data: https:; font-src 'self' data:; connect-src 'self'; frame-ancestors 'self'; base-uri 'self'; form-action 'self'; object-src 'none'- Deploy it in report-only mode.Send it as
Content-Security-Policy-Report-Only. The browser blocks nothing and lists every violation in the developer console (and to areport-toendpoint, if you set one up). - Browse the whole site.Open key pages, the checkout, the contact form and the admin area with the console open. Add each legitimate source, such as your analytics or payment provider, to the right directive.
- Remove inline scripts.Move them into files, or allow individual ones with a per-response nonce or a hash. Avoid
'unsafe-inline'inscript-src, which cancels most of CSP's XSS protection. - Enforce.When the console stays clean for a week, rename the header to
Content-Security-Policy.
A nonce is a random value generated for each response and placed both in the header ('nonce-…') and on each allowed script tag. It must be new on every page load; a fixed value gives no protection.
7. Cross-origin isolation headers
Cross-Origin-Opener-Policy: same-origin keeps other sites' windows from keeping a handle on yours. It can break "log in with…" and payment pop-ups, so test those flows, or use same-origin-allow-popups.
Cross-Origin-Embedder-Policy: require-corp is only needed for features such as SharedArrayBuffer. It blocks third-party embeds that don't opt in, so most sites should leave it out.
8. Setting the headers
Apache and .htaccess (Domain India cPanel and DirectAdmin)
Our shared hosting runs the Apache web server with mod_headers loaded, and .htaccess rules are allowed on cPanel, DirectAdmin and Webuzo. Add this to the .htaccess in your site's folder (usually public_html), above any WordPress block:
<IfModule mod_headers.c>
Header always set Strict-Transport-Security "max-age=300"
Header always set X-Content-Type-Options "nosniff"
Header always set Referrer-Policy "strict-origin-when-cross-origin"
Header always set X-Frame-Options "SAMEORIGIN"
Header always set Permissions-Policy "camera=(), microphone=(), geolocation=(), payment=()"
Header always set Content-Security-Policy-Report-Only "default-src 'self'; img-src 'self' data: https:; style-src 'self' 'unsafe-inline'; frame-ancestors 'self'; base-uri 'self'; object-src 'none'"
</IfModule>Use Header always set, so the headers are also sent on error and redirect responses. A typing mistake in .htaccess gives a 500 error, so keep a copy of the working file. On cPanel, a caching layer in front of Apache can keep serving an older copy of a page for up to 120 minutes; add ?t=1 to the URL when you test.
nginx (your own VPS)
In the server block, then test and reload:
add_header Strict-Transport-Security "max-age=31536000; includeSubDomains" always;
add_header X-Content-Type-Options "nosniff" always;
add_header Referrer-Policy "strict-origin-when-cross-origin" always;
add_header X-Frame-Options "SAMEORIGIN" always;
add_header Content-Security-Policy-Report-Only "default-src 'self'" always;Without always, nginx sends the header only on successful responses. Also note that an add_header inside a location block replaces, rather than adds to, the ones set in server.
Node.js (Express)
The helmet package sets sensible defaults in one line, and you can tune CSP:
import helmet from 'helmet';
app.use(helmet({
contentSecurityPolicy: {
directives: {
"script-src": ["'self'"],
"img-src": ["'self'", "data:", "https:"],
},
},
}));9. Test your headers
- From a terminal:
curl -sI https://yourdomain.com/shows every header. Check a page, an image and a missing URL. - Online scanners: securityheaders.com and Mozilla's HTTP Observatory grade your headers and explain what is missing.
- In the browser: the developer tools' Network tab shows the response headers, and the Console lists CSP violations.
Aim for a clean scan without breaking anything. A top grade matters less than a policy you can keep up to date.
10. Common mistakes
- Sending HSTS with
includeSubDomainswhile a subdomain still has no certificate. - Adding
'unsafe-inline'toscript-srcto silence CSP errors. - Setting a header twice with different values (for example in
.htaccessand in a plugin). Browsers may reject both. - Forgetting headers on error pages (
alwaysin Apache and nginx fixes this). - Copying a strict CSP from another site without testing in report-only mode first.
11. Headers on Domain India hosting
Headers protect your visitors in the browser; the server side is covered separately. Our cPanel servers run Imunify360 with a ModSecurity web application firewall, and Imunify360 also runs on our DirectAdmin servers. The two work together: the firewall filters malicious requests to the server, and your headers limit what the browser will do with your pages. For firewall false positives, see Configuring ModSecurity in cPanel.
- 25 GB NVMe SSD Storage
- 50 GB Monthly Bandwidth
- 1 Website
- 10 Email Accounts
- 10 GB NVMe SSD Storage
- 50 GB Monthly Bandwidth
- 1 Website
- 5 Email Accounts
Prices on the cards are live and exclude 18% GST. Every shared plan includes free SSL, which you need before you add HSTS.
Which security headers should every website send?
At minimum Strict-Transport-Security, X-Content-Type-Options set to nosniff, a Referrer-Policy such as strict-origin-when-cross-origin, and a framing rule (frame-ancestors in CSP or X-Frame-Options). Add a Content-Security-Policy after testing it in report-only mode.
Will security headers slow my site down?
No. They are a few short lines in each response and have no noticeable effect on speed.
Can I add security headers on Domain India shared hosting?
Yes. Domain India cPanel and DirectAdmin hosting runs Apache with mod_headers, and .htaccess rules are allowed, so you can add Header always set lines to the .htaccess file in your site's folder.
How do I test a Content-Security-Policy without breaking my site?
Send it as Content-Security-Policy-Report-Only. The browser blocks nothing but lists every violation in the developer console. Fix the sources it reports, then switch the header name to Content-Security-Policy.
Do security headers replace a web application firewall?
No. Headers instruct the browser, while a firewall filters requests on the server. Use both, and keep writing secure code, because neither replaces escaping output and validating input.
Should I still use X-XSS-Protection?
No. Modern browsers ignore it. Use a Content-Security-Policy instead, and either leave X-XSS-Protection out or set it to 0.
Why don't my new headers show up straight away?
On cPanel hosting a cache in front of Apache can serve an older copy of a page for up to 120 minutes. Add a query string such as ?t=1 to the URL when you test, or check with curl -sI.
Ready to harden your site? Add the headers above, then read How to use OWASP security guidelines for the code side. For a new site, compare cPanel hosting and DirectAdmin hosting, or open a support ticket if a header change breaks your site.
Free SSL, a server-side web application firewall and .htaccess control on every shared plan, with 24/7 live chat support.
See hosting plans