Web Application Security

Security Headers Explained: CSP, HSTS, X-Frame-Options, and More

By Domain India Security Team · DomainIndia Security EngineeringPublished 10 min read
Knowledge base article
Contents (14 sections)

Security headers are a few lines of configuration that tell the browser how to treat your site: always use HTTPS, never let another site frame your pages, never guess a file's type, and run only the scripts you allow. They cost nothing and take minutes to add. This guide explains the headers that matter in 2026, the values to start with, and how to set them on Apache (including Domain India shared hosting), nginx and Node.js.

Key takeaways

Start with four headers that rarely break anything: Strict-Transport-Security, X-Content-Type-Options: nosniff, Referrer-Policy and a framing rule (frame-ancestors in CSP, or X-Frame-Options). Then add a Content-Security-Policy in report-only mode, fix what it reports, and enforce it. On Domain India cPanel and DirectAdmin hosting, you set them in .htaccess with Header always set.

1. Why headers matter

Every HTTP response carries headers as well as content. A handful of them are instructions to the browser. Used well, they block whole classes of attack, such as HTTPS downgrades on public Wi-Fi, clickjacking, MIME sniffing and many cross-site scripting (XSS) injections, without changing your application code.

They are a second line of defence, not a replacement for secure code. Escape output, validate input and keep your CMS and plugins updated first; headers catch what slips through.

2. The headers at a glance

HeaderProtects againstStarting valueRisk of breaking the site
Strict-Transport-SecurityHTTPS downgrade and cookie theft over HTTPmax-age=300 at first, then a yearLow, once every page works over HTTPS
X-Content-Type-OptionsBrowsers running an upload as scriptnosniffVery low
Referrer-PolicyLeaking full URLs to other sitesstrict-origin-when-cross-originVery low
Framing (frame-ancestors, X-Frame-Options)Clickjacking'self' / SAMEORIGINLow, unless another site embeds yours
Permissions-PolicyMisuse of camera, microphone, locationDisable what you don't useLow
Content-Security-PolicyXSS and injected scriptsReport-only firstHigh until tuned
Cross-Origin-Opener-PolicyCross-window attackssame-originMedium: can break login pop-ups

3. Strict-Transport-Security (HSTS)

HSTS tells the browser to use HTTPS for your site from now on, even if someone types http://.

text
Strict-Transport-Security: max-age=31536000; includeSubDomains
  • max-age is how long, in seconds, the browser remembers the rule. One year is typical.
  • includeSubDomains covers every subdomain. Add it only when all your subdomains, including webmail or old test sites, have valid HTTPS.
  • preload asks browsers to ship your domain with HTTPS built in (submitted at hstspreload.org). It is slow to undo, so add it last, if at all.
Start small with HSTS

Browsers remember HSTS for the whole max-age, and you cannot take it back early. Begin with max-age=300 (five minutes), check every page and subdomain over HTTPS, then raise it step by step to a year. Make sure your SSL certificate renews automatically before you commit.

4. X-Content-Type-Options, Referrer-Policy and framing

These three are safe on almost any site.

text
X-Content-Type-Options: nosniff
Referrer-Policy: strict-origin-when-cross-origin
X-Frame-Options: SAMEORIGIN
  • nosniff stops the browser guessing a file's type, so an uploaded "image" can't be run as a script.
  • strict-origin-when-cross-origin sends the full URL within your own site, only your domain name to other HTTPS sites, and nothing when a link leads from HTTPS to HTTP. It is already the browser default, but setting it makes your intent explicit.
  • Framing: the modern control is frame-ancestors inside your CSP, for example frame-ancestors 'self'. X-Frame-Options is the older header; keep it for older browsers, with the same meaning. Use DENY if nobody, including you, needs to frame the page.

X-XSS-Protection is obsolete. Modern browsers ignore it, so leave it out or set it to 0.

5. Permissions-Policy

Turn off browser features your site never uses, so injected code cannot use them either:

text
Permissions-Policy: camera=(), microphone=(), geolocation=(), payment=()

Empty brackets mean "no one". To allow a feature on your own pages only, write geolocation=(self).

6. Content-Security-Policy (CSP)

CSP lists where scripts, styles, images, fonts and connections may come from. A strict policy stops most injected scripts from running. It is also the header most likely to break your site, because analytics tags, chat widgets and inline scripts all need to be allowed.

A reasonable starting policy:

text
Content-Security-Policy: default-src 'self'; script-src 'self'; style-src 'self' 'unsafe-inline'; img-src 'self' data: https:; font-src 'self' data:; connect-src 'self'; frame-ancestors 'self'; base-uri 'self'; form-action 'self'; object-src 'none'
  1. Deploy it in report-only mode.
    Send it as Content-Security-Policy-Report-Only. The browser blocks nothing and lists every violation in the developer console (and to a report-to endpoint, if you set one up).
  2. Browse the whole site.
    Open key pages, the checkout, the contact form and the admin area with the console open. Add each legitimate source, such as your analytics or payment provider, to the right directive.
  3. Remove inline scripts.
    Move them into files, or allow individual ones with a per-response nonce or a hash. Avoid 'unsafe-inline' in script-src, which cancels most of CSP's XSS protection.
  4. Enforce.
    When the console stays clean for a week, rename the header to Content-Security-Policy.

A nonce is a random value generated for each response and placed both in the header ('nonce-…') and on each allowed script tag. It must be new on every page load; a fixed value gives no protection.

7. Cross-origin isolation headers

Cross-Origin-Opener-Policy: same-origin keeps other sites' windows from keeping a handle on yours. It can break "log in with…" and payment pop-ups, so test those flows, or use same-origin-allow-popups.

Cross-Origin-Embedder-Policy: require-corp is only needed for features such as SharedArrayBuffer. It blocks third-party embeds that don't opt in, so most sites should leave it out.

8. Setting the headers

Apache and .htaccess (Domain India cPanel and DirectAdmin)

Our shared hosting runs the Apache web server with mod_headers loaded, and .htaccess rules are allowed on cPanel, DirectAdmin and Webuzo. Add this to the .htaccess in your site's folder (usually public_html), above any WordPress block:

apache
<IfModule mod_headers.c>
    Header always set Strict-Transport-Security "max-age=300"
    Header always set X-Content-Type-Options "nosniff"
    Header always set Referrer-Policy "strict-origin-when-cross-origin"
    Header always set X-Frame-Options "SAMEORIGIN"
    Header always set Permissions-Policy "camera=(), microphone=(), geolocation=(), payment=()"
    Header always set Content-Security-Policy-Report-Only "default-src 'self'; img-src 'self' data: https:; style-src 'self' 'unsafe-inline'; frame-ancestors 'self'; base-uri 'self'; object-src 'none'"
</IfModule>

Use Header always set, so the headers are also sent on error and redirect responses. A typing mistake in .htaccess gives a 500 error, so keep a copy of the working file. On cPanel, a caching layer in front of Apache can keep serving an older copy of a page for up to 120 minutes; add ?t=1 to the URL when you test.

nginx (your own VPS)

In the server block, then test and reload:

nginx
add_header Strict-Transport-Security "max-age=31536000; includeSubDomains" always;
add_header X-Content-Type-Options "nosniff" always;
add_header Referrer-Policy "strict-origin-when-cross-origin" always;
add_header X-Frame-Options "SAMEORIGIN" always;
add_header Content-Security-Policy-Report-Only "default-src 'self'" always;

Without always, nginx sends the header only on successful responses. Also note that an add_header inside a location block replaces, rather than adds to, the ones set in server.

Node.js (Express)

The helmet package sets sensible defaults in one line, and you can tune CSP:

javascript
import helmet from 'helmet';

app.use(helmet({
  contentSecurityPolicy: {
    directives: {
      "script-src": ["'self'"],
      "img-src": ["'self'", "data:", "https:"],
    },
  },
}));

9. Test your headers

  • From a terminal: curl -sI https://yourdomain.com/ shows every header. Check a page, an image and a missing URL.
  • Online scanners: securityheaders.com and Mozilla's HTTP Observatory grade your headers and explain what is missing.
  • In the browser: the developer tools' Network tab shows the response headers, and the Console lists CSP violations.

Aim for a clean scan without breaking anything. A top grade matters less than a policy you can keep up to date.

10. Common mistakes

  • Sending HSTS with includeSubDomains while a subdomain still has no certificate.
  • Adding 'unsafe-inline' to script-src to silence CSP errors.
  • Setting a header twice with different values (for example in .htaccess and in a plugin). Browsers may reject both.
  • Forgetting headers on error pages (always in Apache and nginx fixes this).
  • Copying a strict CSP from another site without testing in report-only mode first.

11. Headers on Domain India hosting

Headers protect your visitors in the browser; the server side is covered separately. Our cPanel servers run Imunify360 with a ModSecurity web application firewall, and Imunify360 also runs on our DirectAdmin servers. The two work together: the firewall filters malicious requests to the server, and your headers limit what the browser will do with your pages. For firewall false positives, see Configuring ModSecurity in cPanel.

cPanel Starter
₹125/mo + GST
  • 25 GB NVMe SSD Storage
  • 50 GB Monthly Bandwidth
  • 1 Website
  • 10 Email Accounts
See plan details
DA Starter
₹100/mo + GST
  • 10 GB NVMe SSD Storage
  • 50 GB Monthly Bandwidth
  • 1 Website
  • 5 Email Accounts
See plan details

Prices on the cards are live and exclude 18% GST. Every shared plan includes free SSL, which you need before you add HSTS.

Which security headers should every website send?

At minimum Strict-Transport-Security, X-Content-Type-Options set to nosniff, a Referrer-Policy such as strict-origin-when-cross-origin, and a framing rule (frame-ancestors in CSP or X-Frame-Options). Add a Content-Security-Policy after testing it in report-only mode.

Will security headers slow my site down?

No. They are a few short lines in each response and have no noticeable effect on speed.

Can I add security headers on Domain India shared hosting?

Yes. Domain India cPanel and DirectAdmin hosting runs Apache with mod_headers, and .htaccess rules are allowed, so you can add Header always set lines to the .htaccess file in your site's folder.

How do I test a Content-Security-Policy without breaking my site?

Send it as Content-Security-Policy-Report-Only. The browser blocks nothing but lists every violation in the developer console. Fix the sources it reports, then switch the header name to Content-Security-Policy.

Do security headers replace a web application firewall?

No. Headers instruct the browser, while a firewall filters requests on the server. Use both, and keep writing secure code, because neither replaces escaping output and validating input.

Should I still use X-XSS-Protection?

No. Modern browsers ignore it. Use a Content-Security-Policy instead, and either leave X-XSS-Protection out or set it to 0.

Why don't my new headers show up straight away?

On cPanel hosting a cache in front of Apache can serve an older copy of a page for up to 120 minutes. Add a query string such as ?t=1 to the URL when you test, or check with curl -sI.

Ready to harden your site? Add the headers above, then read How to use OWASP security guidelines for the code side. For a new site, compare cPanel hosting and DirectAdmin hosting, or open a support ticket if a header change breaks your site.

Secure hosting for your website

Free SSL, a server-side web application firewall and .htaccess control on every shared plan, with 24/7 live chat support.

See hosting plans

Was this article helpful?

Your answer helps us decide what to improve next.

Still need help? Open a support ticket and our team will reply.

Prefer an app? Add this site to your home screen.Get the app
Security Headers Explained: CSP, HSTS & More