HTTP headers · Quick reference
HTTP response headers reference: security, cookies and caching
Use this reference beside a header report. Match each policy to the resource and the browser journeys it supports. HeaderScan reads the final response; a recognized header value does not prove that the entire application is secure.
Security headers
Start with the actual HTML response. Apply changes in staging and inspect browser behavior as well as the deployed headers.
| Header | Purpose | What to verify |
|---|---|---|
| Content-Security-Policy | Limits sources for scripts and other resources. | Inventory dependencies; test a tailored Report-Only policy before enforcement. |
| Strict-Transport-Security | Tells a browser to use HTTPS for this host. | Send over HTTPS; includeSubDomains affects every covered subdomain. |
| X-Content-Type-Options | nosniff limits MIME type guessing. | Set the correct Content-Type and send one nosniff value. |
| Referrer-Policy | Controls referrer information shared on requests. | Choose a policy that fits navigation and analytics requirements. |
| Content-Security-Policy: frame-ancestors | Controls which parents may embed this document. | Explicitly allow required parents; default-src does not supply this directive. |
| X-Frame-Options | Older framing control using DENY or SAMEORIGIN. | Review it alongside frame-ancestors and test required embedding flows. |
| Permissions-Policy | Controls access to selected browser features. | Check which features the application needs; presence alone is not a security result. |
| Access-Control-Allow-Origin | Participates in cross-origin resource access. | Test allowed and denied Origins and preflights; a normal GET is insufficient. |
| Cross-Origin-Opener-Policy | Controls sharing of a browsing context group with other documents. | Test cross-origin popup flows, including login and payments, before restricting them. |
| Cross-Origin-Resource-Policy | Restricts cross-origin or cross-site loading of this resource in applicable no-cors requests. | Check which sites must embed the resource; this is separate from CORS. |
| Server / X-Powered-By | May disclose implementation details. | Remove unnecessary versions and maintain the underlying software. |
Reference: MDN: HTTP headers
Caching and response variants
Select a policy per response type. Investigate cookie-bearing shared-cache responses with the application and CDN owners; the headers alone do not reveal stored cache contents.
| Header or directive | Meaning | Example use |
|---|---|---|
| Cache-Control: no-store | Requests that caches do not store this response. | Sensitive account output. |
| Cache-Control: no-cache | Allows storage but requires validation before reuse. | Content that must be checked before reuse. |
| Cache-Control: private | Excludes shared caches; browser storage remains possible. | Personalized content with an appropriate browser policy. |
| max-age / s-maxage | Freshness lifetime; s-maxage targets shared caches. | Choose separately for browser and shared-cache reuse. |
| ETag / Last-Modified | Validators for conditional requests. | Retest revalidation when stored content changes. |
| Vary | Names request fields that select response variants. | Origin-dependent CORS responses may need Vary: Origin. |
Reference: MDN: Cache-Control
Inspect the deployed GET response
This command discards the body and prints the headers from the requested URL. It does not follow redirects. Inspect the final URL separately or use HeaderScan to follow the chain.
curl --silent --show-error --dump-header - --output /dev/null https://example.com/ - Compare a successful HTML page, an asset and an error response.
- Check for conflicting policies added by the app, web server or CDN.
- Rescan after deployment and test affected browser flows.
Reference: curl: command-line options
From scan to solution
Understand what your headers are telling you
HTTP response headers control how browsers load a page, store its content and handle cookies. Use HeaderScan to inspect the final response, then use these guides to turn a missing header or an unexpected value into a focused change. Start with the policy that affects your page, and check the response again after deploying it.
HTTP security headers: what to check first
Understand CSP, HSTS and framing protection, then work through security header findings without breaking your website.
Read guide CachingCache-Control explained: no-cache, no-store and private
Choose a cache policy for public assets and personal pages, and understand why no-cache still allows storage.
Read guide CookiesSecure, HttpOnly and SameSite cookies explained
Learn what each cookie attribute controls and how to review session cookies without breaking login or payment flows.
Read guide