Security Headers Guide

Complete guide to HTTP security headers and how they improve your website's security and SEO rankings.

What Are Security Headers?

Security headers are HTTP response headers that tell browsers how to behave when handling your website's content. They provide an additional layer of security by enabling browser-side protections against common attacks like XSS, clickjacking, and code injection.

💡 SEO Impact: Google considers site security as a ranking factor. Properly configured security headers demonstrate that you take security seriously, which can positively impact your search rankings and user trust.

Essential Security Headers

🔒 HSTS (HTTP Strict Transport Security)

Forces browsers to only connect to your site over HTTPS, preventing downgrade attacks and cookie hijacking.

Recommended Configuration:

Strict-Transport-Security: max-age=31536000; includeSubDomains; preload

Parameters:

  • max-age: Duration in seconds (31536000 = 1 year)
  • includeSubDomains: Apply to all subdomains
  • preload: Submit to HSTS preload list

SEO Impact: Google prefers HTTPS sites. HSTS ensures all connections are secure, improving rankings and user trust.

🛡️ CSP (Content Security Policy)

Controls which resources can be loaded and executed on your page, preventing XSS attacks and data injection.

Example Configuration:

Content-Security-Policy: default-src 'self'; script-src 'self' 'unsafe-inline'; style-src 'self' 'unsafe-inline'; img-src 'self' data: https:; font-src 'self' data:; connect-src 'self';

Common Directives:

  • default-src: Fallback for all resource types
  • script-src: Controls JavaScript sources
  • style-src: Controls CSS sources
  • img-src: Controls image sources
  • upgrade-insecure-requests: Upgrades HTTP to HTTPS

SEO Impact: Prevents XSS attacks that could inject spam or malicious content, protecting your site's reputation and rankings.

🖼️ X-Frame-Options

Prevents your site from being embedded in iframes, protecting against clickjacking attacks.

Recommended Configuration:

X-Frame-Options: DENY

Or use SAMEORIGIN if you need to frame your own pages

Options:

  • DENY: Cannot be framed by any site
  • SAMEORIGIN: Can only be framed by same origin
  • ALLOW-FROM uri: Deprecated, use CSP frame-ancestors instead

SEO Impact: Prevents clickjacking attacks that could trick users into unwanted actions, maintaining site trust.

📄 X-Content-Type-Options

Prevents browsers from MIME-sniffing responses, reducing the risk of drive-by downloads.

Configuration:

X-Content-Type-Options: nosniff

SEO Impact: Prevents MIME-type confusion attacks that could serve malicious content.

🔗 Referrer-Policy

Controls how much referrer information is sent with requests to other sites.

Recommended Configuration:

Referrer-Policy: strict-origin-when-cross-origin

Common Policies:

  • no-referrer: Never send referrer
  • strict-origin-when-cross-origin: Send full URL for same-origin, origin only for cross-origin
  • no-referrer-when-downgrade: Default behavior

SEO Impact: Balances privacy with analytics needs. Affects referral tracking in Google Analytics.

🎛️ Permissions-Policy

Controls which browser features and APIs can be used on your site and in embedded iframes.

Example Configuration:

Permissions-Policy: geolocation=(), microphone=(), camera=(), payment=()

Common Features to Control:

  • geolocation: Location access
  • microphone/camera: Media device access
  • payment: Payment Request API
  • autoplay: Video/audio autoplay

SEO Impact: Improves privacy and security by restricting sensitive features.

How to Implement Security Headers

Apache (.htaccess)

Header always set Strict-Transport-Security "max-age=31536000; includeSubDomains; preload"
Header always set X-Frame-Options "DENY"
Header always set X-Content-Type-Options "nosniff"
Header always set X-XSS-Protection "1; mode=block"
Header always set Referrer-Policy "strict-origin-when-cross-origin"
Header always set Permissions-Policy "geolocation=(), microphone=(), camera=()"
Header always set Content-Security-Policy "default-src 'self'; script-src 'self' 'unsafe-inline'; style-src 'self' 'unsafe-inline';"

Nginx

add_header Strict-Transport-Security "max-age=31536000; includeSubDomains; preload" always;
add_header X-Frame-Options "DENY" always;
add_header X-Content-Type-Options "nosniff" always;
add_header X-XSS-Protection "1; mode=block" always;
add_header Referrer-Policy "strict-origin-when-cross-origin" always;
add_header Permissions-Policy "geolocation=(), microphone=(), camera=()" always;
add_header Content-Security-Policy "default-src 'self'; script-src 'self' 'unsafe-inline'; style-src 'self' 'unsafe-inline';" always;

PHP

header("Strict-Transport-Security: max-age=31536000; includeSubDomains; preload");
header("X-Frame-Options: DENY");
header("X-Content-Type-Options: nosniff");
header("X-XSS-Protection: 1; mode=block");
header("Referrer-Policy: strict-origin-when-cross-origin");
header("Permissions-Policy: geolocation=(), microphone=(), camera=()");
header("Content-Security-Policy: default-src 'self'; script-src 'self' 'unsafe-inline'; style-src 'self' 'unsafe-inline';");

Security Headers & SEO

🔍

Google's Security Ranking Factor

Google considers site security as a ranking signal. Sites with proper security headers demonstrate security best practices, which can positively impact rankings.

🛡️

User Trust & Engagement

Secure sites build user trust. Better security leads to lower bounce rates and higher engagement, which are indirect SEO signals.

⚡

HTTPS Requirement

HSTS ensures all connections are HTTPS. Google has confirmed HTTPS is a ranking factor, and HSTS strengthens this.

🚫

Malware Protection

CSP and other headers prevent code injection attacks that could add spam or malicious content, protecting your SEO.

📱

Mobile Security

Security headers protect mobile users too. With mobile-first indexing, mobile security is crucial for SEO.

Common Mistakes to Avoid

❌ Using 'unsafe-inline' in CSP

While convenient, 'unsafe-inline' weakens XSS protection. Use nonces or hashes instead for inline scripts.

❌ Short HSTS max-age

max-age should be at least 1 year (31536000 seconds). Shorter durations don't provide adequate protection.

❌ Missing includeSubDomains in HSTS

Subdomains can be attack vectors. Always include includeSubDomains in your HSTS header.

❌ Exposing Server/X-Powered-By Headers

These headers reveal your technology stack, helping attackers target specific vulnerabilities. Hide them.

❌ Not Testing After Implementation

Always test your site after adding security headers. Some configurations can break functionality.

Testing & Validation

🔧

Use Our Security Headers Analyzer

Our tool checks all major security headers and provides a security score with detailed recommendations.

Analyze Your Headers →
🌐

Browser DevTools

Open DevTools (F12) → Network tab → Click on your page → Headers tab to view all response headers.

📊

SecurityHeaders.com

Third-party service that provides detailed security header analysis and grading.

🔍

CSP Evaluator

Google's CSP Evaluator helps you validate and improve your Content Security Policy.

Ready to Check Your Security Headers?

Analyze your website's security headers and get a detailed security score with recommendations.

Analyze Security Headers

100% Free • No Registration • Instant Results