Lessons

HTTP Headers

There are hundreds of different kinds of headlines. In this check we check the following:

  • Specify the encoding for HTML documents. Without this, browsers may display the page incorrectly.
  • Refrain from the Link header. It is better to use analog meta tags. They are easier to manage. The exceptions are text files of PDF, DJVU, etc. formats, the contents of which are indexed by search engines. They do not have the ability to use an HTML tag to specify different language versions.
  • Remove the outdated headers Public-Key-Pins, Expect-CT, `X-XSS-Protection’.
  • Use the ‘X-Frame-Options’ and Content-Security-Policy headers only for HTML pages.
  • Use the ‘X-Content-Type-Options` header only for HTML, XML, CSS, JavaScrit links.
  • For cookies, pass the Secure flag.

Remark: it is not possible to delete the Server header from the Apache web server, only to make it empty. To do this, add/change the following directives in the /etc/apache2/conf-available/security.conf file: “ ServerTokens Prod ServerSignature Off SecServerSignature ” ” “`

Check your website
It's free and will take from 11 to 45 seconds

We use cookies. By continuing to use the site, you agree to the processing of personal data in accordance with privacy policy. I agree