An A+ header grade protects your users in the browser, but attackers start one layer lower: exposed servers, forgotten ports and unpatched software. Here's how to see your domain the way they do.
Next.js emits inline hydration scripts, so a naive script-src blocks your own app. Here is the clean nonce + strict-dynamic setup in middleware, plus the styled-jsx and next/image gotchas.
Nginx sets response headers with add_header. Here is a copy-paste server block for HSTS, X-Frame-Options, nosniff and more — plus the inheritance trap that silently drops your headers inside a location block.
Apache sets headers with mod_headers. Here is a copy-paste config for HSTS, X-Frame-Options, nosniff and more — and why you want Header always set rather than Header set.
Proxied through Cloudflare? Add HSTS, X-Frame-Options, Referrer-Policy and more at the edge with Managed Transforms and Transform Rules — no origin changes required.
CSP Level 3 replaces fragile allowlists with nonce-based policies and strict-dynamic to stop XSS. Learn how to pair it with Trusted Types, SRI, and sanitization for layered defense.
HeaderTest is out of beta. Here's what changed: a new three-category scoring system, domain history pages with score trends, and a more accurate analysis engine.
A practical walkthrough of Content Security Policy — what it actually does, how browsers enforce it, and how to roll one out without breaking your site.
The security headers that actually matter, what each one does, and copy-paste values to get you started. No fluff, just the headers you need.