The six headers we check
- Strict-Transport-Security (HSTS): tells browsers to use HTTPS only for this host from now on. Browsers ignore it when it arrives over plain http.
- Content-Security-Policy (CSP): limits where scripts, styles, frames and other resources may load from. The Report-Only version only reports violations and blocks nothing.
- X-Content-Type-Options: nosniff is the only valid value. It stops the browser guessing a file's type, and makes it refuse scripts and stylesheets served with the wrong type.
- X-Frame-Options or CSP frame-ancestors: stops other sites from loading your pages in a frame (clickjacking). X-Frame-Options does nothing in a meta tag; it must be a header.
- Referrer-Policy: how much of the page address is sent to other sites in the Referer header.
- Permissions-Policy: switches off browser features the site doesn't use, such as the camera, microphone or location.
How to read the result
OK means the header is set and does its job. Fix means it's missing or weak in a way worth changing. Note means it's optional or a judgement call: a CSP that allows inline scripts, a report-only policy, or no Referrer-Policy when the browser default is already reasonable.
The verdicts use the same rules as the security section of the full report. HSTS counts as short under 180 days; MDN notes that HSTS preloading needs at least one year (31536000 seconds) plus includeSubDomains.
Common fixes
- nginx: add_header lines in the server block, with the always parameter so they're sent on error pages too. Example: add_header X-Content-Type-Options "nosniff" always;
- Apache: Header always set lines in the virtual host or .htaccess (mod_headers must be enabled).
- Cloudflare: HSTS has its own switch on the SSL/TLS > Edge Certificates page.
- Start a CSP in Report-Only mode, read the reports for a while, then switch the same policy to Content-Security-Policy.
- Send HSTS only once every subdomain works over HTTPS if you add includeSubDomains. Browsers remember it for max-age seconds.
What these headers don't do
Headers make some attacks harder in the browser. They don't patch an outdated plugin, a weak password or a vulnerable server. AdSense and Google Search don't publish any requirement for these headers; they're about protecting visitors and your own site.