Strict-Transport-Security: browsers only use HTTPS for the site, so a network attacker cannot downgrade it. A year or more, with includeSubDomains.
Content-Security-Policy: where scripts, styles and frames may come from. The strongest single defence against injected scripts, if it avoids 'unsafe-inline'.
X-Frame-Options or frame-ancestors: stops other sites from framing the page to trick clicks.
X-Content-Type-Options: nosniff, Referrer-Policy, Permissions-Policy and Cross-Origin-Opener-Policy: smaller holes closed.
Cookies.
A session cookie should carry Secure (HTTPS only), HttpOnly (out of reach of page scripts) and SameSite (not sent on most cross-site requests). The prefix __Host- pins a cookie to one host. Hivex reads only each cookie's name and flags, never its value.
Adding the headers.
They are set by the web server, the hosting platform or a CDN in front of it. Add one at a time and test, starting with nosniff and HSTS. Build the Content Security Policy in report-only mode first (Content-Security-Policy-Report-Only), watch what it would block, then switch it on.
Questions people ask.
Which security headers should every website send?
Strict-Transport-Security, a Content-Security-Policy, X-Content-Type-Options: nosniff, a framing rule (X-Frame-Options or frame-ancestors) and a Referrer-Policy; Permissions-Policy and Cross-Origin-Opener-Policy add more.
How is the grade worked out?
Each check earns points (HSTS and the Content Security Policy count most), headers that reveal the software cost a few, and the total maps to a letter. It is Hivex's own weighting of OWASP's recommendations; every point is shown.
What is HSTS preload?
A list built into browsers of sites that are only ever opened over HTTPS, even on the first visit. A site joins at hstspreload.org once its HSTS header has max-age of a year or more, includeSubDomains and preload.
Why is 'unsafe-inline' a problem in a Content Security Policy?
It lets any inline script run, so an attacker who injects a script tag gets it executed and the policy stops almost nothing. Use nonces or hashes for the inline scripts you need.
Should I still send X-XSS-Protection?
No. Current browsers removed the filter it controlled. Set it to 0 or leave it out, and rely on a Content Security Policy.
Hivex index
Short names, still free to register.
Starting something new? Hivex keeps a live index of short, brandable .si names nobody has claimed yet, each checked with the registry.
Hivex's free JSON API and MCP server check domains, DNS and registration records from your own code or from AI assistants that speak MCP. No key needed.