What response headers tell you
Headers carry the decisions a server has made that never appear in the page itself: how long a response may be cached, whether it was served from a CDN edge, which compression was applied, whether a redirect happened and whether it was permanent.
That makes them the first thing to check when behaviour does not match expectation. A page serving stale content, a redirect chain costing you three round trips, or a CDN miss on every request are all visible in the headers and invisible in the HTML.
The security headers worth having
Strict-Transport-Security tells browsers to use HTTPS for your domain for a stated period, closing the window where a first plain-HTTP request can be intercepted. Content-Security-Policy limits where scripts may load from and is the control that decides how damaging a cross-site scripting bug turns out to be.
X-Content-Type-Options with the value nosniff stops browsers second-guessing your declared content types. X-Frame-Options and the frame-ancestors CSP directive prevent your pages being embedded in someone else site, which is what clickjacking depends on. Referrer-Policy controls how much of your URL is leaked to third parties - which matters whenever a path contains a token or an identifier.
Permissions-Policy declares which browser features a page may use, so camera and microphone access cannot be requested by anything you did not intend to allow.
Checking headers you do not control
Running this against a vendor or a partner before integrating is a quick way to judge how seriously they take their own configuration. It is also the fastest way to see how a competitor CDN is set up, or to confirm that a third-party script host is not serving with a content type that will be sniffed.
Frequently asked questions
- Which security headers should every site send?
- Strict-Transport-Security, Content-Security-Policy, X-Content-Type-Options, a framing restriction via X-Frame-Options or frame-ancestors, and Referrer-Policy. Permissions-Policy is worth adding wherever device access is a concern.
- What does nosniff actually do?
- It stops browsers guessing a content type that differs from the one you declared. Without it, a file served with the wrong type can be interpreted as a script, which is a real attack path.
- Is a missing Content-Security-Policy serious?
- It means any cross-site scripting bug you have is maximally damaging. CSP does not prevent XSS; it limits what an injected script can do and where it can send data.
- Can I check headers for a site I do not own?
- Yes. Response headers are public information returned to every visitor, so checking any URL is entirely ordinary.