# Security headers

> HTTP response headers that tell browsers how to handle the page safely — HSTS, CSP, X-Frame-Options — free defences most sites skip.

A handful of response headers close entire attack classes for zero runtime cost: HSTS forces HTTPS forever after the first visit, X-Frame-Options stops the page being embedded in a hostile site, X-Content-Type-Options stops the browser second-guessing file types, Referrer-Policy controls what leaks in links.

The big one is the content security policy — a whitelist of where scripts, styles and connections may come from, which makes most XSS dead on arrival. It takes real work on a legacy site because it enumerates every legitimate source; on a new build it should ship on day one.

## Related terms

- https://dfieldsolutions.com/en/glossary/csp.md
- https://dfieldsolutions.com/en/glossary/tls.md
- https://dfieldsolutions.com/en/glossary/xss.md

---

Source: https://dfieldsolutions.com/en/glossary/security-headers
DField Solutions — Dunakeszi, Hungary — dezso@dfieldsolutions.com
Booking: see https://dfieldsolutions.com/en/contact
