A handful of extra instructions a web server can send with every response, telling the browser how to handle the page more safely.
Tells a browser "always connect to this site over HTTPS, never plain HTTP, for the next N days" — even if a user types the address without "https" or clicks an old http:// link. Without it, that first connection attempt is a brief window where a network attacker could intercept it before the redirect happens.
Restricts which sources a page is allowed to load scripts, styles, and other content from. Its main practical value is limiting the damage if an attacker manages to inject malicious script into a page (via a vulnerable plugin, a compromised third-party widget, or a form that doesn't sanitise input) — a good CSP stops that injected script from running or from sending stolen data somewhere else.
Controls whether other sites are allowed to embed your page inside an iframe. Without it, an attacker can load your real page inside an invisible frame on their own malicious site and trick visitors into clicking things on your page without realising it — a technique called clickjacking.
Cookies can be marked Secure (only ever sent over HTTPS) and HttpOnly (invisible to JavaScript, so a script injected via an XSS bug can't steal it directly). Both are simple flags set when a cookie is created — missing them doesn't cause an obvious visible problem, but it does remove a layer of protection that costs nothing to enable.
None of these headers are visible to a normal visitor — there's no icon or warning shown for a missing one, which is exactly why they're so commonly overlooked. They don't fix an underlying vulnerability by themselves, but they meaningfully reduce what an attacker can actually do if one exists.
Want to know where your own domain stands? CBWatch checks this — and eight other categories — in about ten seconds, free, no signup.
Run a free scan →Want CBWatch to catch this automatically going forward? See what monitoring includes →