HTTP headers · Quick reference

HTTP response headers reference: security, cookies and caching

Use this reference beside a header report. Match each policy to the resource and the browser journeys it supports. HeaderScan reads the final response; a recognized header value does not prove that the entire application is secure.

Security headers

Start with the actual HTML response. Apply changes in staging and inspect browser behavior as well as the deployed headers.

Security headers
HeaderPurposeWhat to verify
Content-Security-Policy Limits sources for scripts and other resources. Inventory dependencies; test a tailored Report-Only policy before enforcement.
Strict-Transport-Security Tells a browser to use HTTPS for this host. Send over HTTPS; includeSubDomains affects every covered subdomain.
X-Content-Type-Options nosniff limits MIME type guessing. Set the correct Content-Type and send one nosniff value.
Referrer-Policy Controls referrer information shared on requests. Choose a policy that fits navigation and analytics requirements.
Content-Security-Policy: frame-ancestors Controls which parents may embed this document. Explicitly allow required parents; default-src does not supply this directive.
X-Frame-Options Older framing control using DENY or SAMEORIGIN. Review it alongside frame-ancestors and test required embedding flows.
Permissions-Policy Controls access to selected browser features. Check which features the application needs; presence alone is not a security result.
Access-Control-Allow-Origin Participates in cross-origin resource access. Test allowed and denied Origins and preflights; a normal GET is insufficient.
Cross-Origin-Opener-Policy Controls sharing of a browsing context group with other documents. Test cross-origin popup flows, including login and payments, before restricting them.
Cross-Origin-Resource-Policy Restricts cross-origin or cross-site loading of this resource in applicable no-cors requests. Check which sites must embed the resource; this is separate from CORS.
Server / X-Powered-By May disclose implementation details. Remove unnecessary versions and maintain the underlying software.

Reference: MDN: HTTP headers

Cookie attributes

Inspect each Set-Cookie header separately. The public scan sees response cookies, not every cookie created after sign-in or by JavaScript.

Cookie attributes
AttributeRoleReview point
Secure Restricts transmission to secure connections. A presence flag: use Secure, not Secure=false.
HttpOnly Blocks access through JavaScript cookie APIs. Use for session identifiers that scripts do not need to read.
SameSite Controls cross-site cookie transmission. Choose for the flow; None requires Secure.
Domain Can extend the cookie to matching subdomains. Omit for a host-only cookie when sharing is unnecessary.
Path Controls which request paths receive the cookie. It is not an authorization boundary.
Max-Age Sets the lifetime in seconds. A value of zero or less deletes the cookie.

Reference: MDN: Set-Cookie

Caching and response variants

Select a policy per response type. Investigate cookie-bearing shared-cache responses with the application and CDN owners; the headers alone do not reveal stored cache contents.

Caching and response variants
Header or directiveMeaningExample use
Cache-Control: no-store Requests that caches do not store this response. Sensitive account output.
Cache-Control: no-cache Allows storage but requires validation before reuse. Content that must be checked before reuse.
Cache-Control: private Excludes shared caches; browser storage remains possible. Personalized content with an appropriate browser policy.
max-age / s-maxage Freshness lifetime; s-maxage targets shared caches. Choose separately for browser and shared-cache reuse.
ETag / Last-Modified Validators for conditional requests. Retest revalidation when stored content changes.
Vary Names request fields that select response variants. Origin-dependent CORS responses may need Vary: Origin.

Reference: MDN: Cache-Control

Inspect the deployed GET response

This command discards the body and prints the headers from the requested URL. It does not follow redirects. Inspect the final URL separately or use HeaderScan to follow the chain.

curl --silent --show-error --dump-header - --output /dev/null https://example.com/
  1. Compare a successful HTML page, an asset and an error response.
  2. Check for conflicting policies added by the app, web server or CDN.
  3. Rescan after deployment and test affected browser flows.

Reference: curl: command-line options

From scan to solution

Understand what your headers are telling you

HTTP response headers control how browsers load a page, store its content and handle cookies. Use HeaderScan to inspect the final response, then use these guides to turn a missing header or an unexpected value into a focused change. Start with the policy that affects your page, and check the response again after deploying it.