Security Headers Guide
Complete guide to HTTP security headers and how they improve your website's security and SEO rankings.
What Are Security Headers?
Security headers are HTTP response headers that tell browsers how to behave when handling your website's content. They provide an additional layer of security by enabling browser-side protections against common attacks like XSS, clickjacking, and code injection.
💡 SEO Impact: Google considers site security as a ranking factor. Properly configured security headers demonstrate that you take security seriously, which can positively impact your search rankings and user trust.
Essential Security Headers
🔒 HSTS (HTTP Strict Transport Security)
Forces browsers to only connect to your site over HTTPS, preventing downgrade attacks and cookie hijacking.
Recommended Configuration:
Strict-Transport-Security: max-age=31536000; includeSubDomains; preload
Parameters:
- max-age: Duration in seconds (31536000 = 1 year)
- includeSubDomains: Apply to all subdomains
- preload: Submit to HSTS preload list
SEO Impact: Google prefers HTTPS sites. HSTS ensures all connections are secure, improving rankings and user trust.
🛡️ CSP (Content Security Policy)
Controls which resources can be loaded and executed on your page, preventing XSS attacks and data injection.
Example Configuration:
Content-Security-Policy: default-src 'self'; script-src 'self' 'unsafe-inline'; style-src 'self' 'unsafe-inline'; img-src 'self' data: https:; font-src 'self' data:; connect-src 'self';
Common Directives:
- default-src: Fallback for all resource types
- script-src: Controls JavaScript sources
- style-src: Controls CSS sources
- img-src: Controls image sources
- upgrade-insecure-requests: Upgrades HTTP to HTTPS
SEO Impact: Prevents XSS attacks that could inject spam or malicious content, protecting your site's reputation and rankings.
🖼️ X-Frame-Options
Prevents your site from being embedded in iframes, protecting against clickjacking attacks.
Recommended Configuration:
X-Frame-Options: DENY
Or use SAMEORIGIN if you need to frame your own pages
Options:
- DENY: Cannot be framed by any site
- SAMEORIGIN: Can only be framed by same origin
- ALLOW-FROM uri: Deprecated, use CSP frame-ancestors instead
SEO Impact: Prevents clickjacking attacks that could trick users into unwanted actions, maintaining site trust.
📄 X-Content-Type-Options
Prevents browsers from MIME-sniffing responses, reducing the risk of drive-by downloads.
Configuration:
X-Content-Type-Options: nosniff
SEO Impact: Prevents MIME-type confusion attacks that could serve malicious content.
🔗 Referrer-Policy
Controls how much referrer information is sent with requests to other sites.
Recommended Configuration:
Referrer-Policy: strict-origin-when-cross-origin
Common Policies:
- no-referrer: Never send referrer
- strict-origin-when-cross-origin: Send full URL for same-origin, origin only for cross-origin
- no-referrer-when-downgrade: Default behavior
SEO Impact: Balances privacy with analytics needs. Affects referral tracking in Google Analytics.
🎛️ Permissions-Policy
Controls which browser features and APIs can be used on your site and in embedded iframes.
Example Configuration:
Permissions-Policy: geolocation=(), microphone=(), camera=(), payment=()
Common Features to Control:
- geolocation: Location access
- microphone/camera: Media device access
- payment: Payment Request API
- autoplay: Video/audio autoplay
SEO Impact: Improves privacy and security by restricting sensitive features.
How to Implement Security Headers
Apache (.htaccess)
Header always set Strict-Transport-Security "max-age=31536000; includeSubDomains; preload" Header always set X-Frame-Options "DENY" Header always set X-Content-Type-Options "nosniff" Header always set X-XSS-Protection "1; mode=block" Header always set Referrer-Policy "strict-origin-when-cross-origin" Header always set Permissions-Policy "geolocation=(), microphone=(), camera=()" Header always set Content-Security-Policy "default-src 'self'; script-src 'self' 'unsafe-inline'; style-src 'self' 'unsafe-inline';"
Nginx
add_header Strict-Transport-Security "max-age=31536000; includeSubDomains; preload" always; add_header X-Frame-Options "DENY" always; add_header X-Content-Type-Options "nosniff" always; add_header X-XSS-Protection "1; mode=block" always; add_header Referrer-Policy "strict-origin-when-cross-origin" always; add_header Permissions-Policy "geolocation=(), microphone=(), camera=()" always; add_header Content-Security-Policy "default-src 'self'; script-src 'self' 'unsafe-inline'; style-src 'self' 'unsafe-inline';" always;
PHP
header("Strict-Transport-Security: max-age=31536000; includeSubDomains; preload");
header("X-Frame-Options: DENY");
header("X-Content-Type-Options: nosniff");
header("X-XSS-Protection: 1; mode=block");
header("Referrer-Policy: strict-origin-when-cross-origin");
header("Permissions-Policy: geolocation=(), microphone=(), camera=()");
header("Content-Security-Policy: default-src 'self'; script-src 'self' 'unsafe-inline'; style-src 'self' 'unsafe-inline';");
Security Headers & SEO
Google's Security Ranking Factor
Google considers site security as a ranking signal. Sites with proper security headers demonstrate security best practices, which can positively impact rankings.
User Trust & Engagement
Secure sites build user trust. Better security leads to lower bounce rates and higher engagement, which are indirect SEO signals.
HTTPS Requirement
HSTS ensures all connections are HTTPS. Google has confirmed HTTPS is a ranking factor, and HSTS strengthens this.
Malware Protection
CSP and other headers prevent code injection attacks that could add spam or malicious content, protecting your SEO.
Mobile Security
Security headers protect mobile users too. With mobile-first indexing, mobile security is crucial for SEO.
Common Mistakes to Avoid
❌ Using 'unsafe-inline' in CSP
While convenient, 'unsafe-inline' weakens XSS protection. Use nonces or hashes instead for inline scripts.
❌ Short HSTS max-age
max-age should be at least 1 year (31536000 seconds). Shorter durations don't provide adequate protection.
❌ Missing includeSubDomains in HSTS
Subdomains can be attack vectors. Always include includeSubDomains in your HSTS header.
❌ Exposing Server/X-Powered-By Headers
These headers reveal your technology stack, helping attackers target specific vulnerabilities. Hide them.
❌ Not Testing After Implementation
Always test your site after adding security headers. Some configurations can break functionality.
Testing & Validation
Use Our Security Headers Analyzer
Our tool checks all major security headers and provides a security score with detailed recommendations.
Analyze Your Headers →Browser DevTools
Open DevTools (F12) → Network tab → Click on your page → Headers tab to view all response headers.
SecurityHeaders.com
Third-party service that provides detailed security header analysis and grading.
CSP Evaluator
Google's CSP Evaluator helps you validate and improve your Content Security Policy.
Ready to Check Your Security Headers?
Analyze your website's security headers and get a detailed security score with recommendations.
Analyze Security Headers100% Free • No Registration • Instant Results