Headers checked and recommended values
| Header | Recommended value |
|---|---|
| Strict-Transport-Security | max-age=31536000; includeSubDomains |
| Content-Security-Policy | A policy listing allowed sources, without 'unsafe-inline' or 'unsafe-eval' where possible |
| X-Frame-Options | SAMEORIGIN (or CSP frame-ancestors) |
| X-Content-Type-Options | nosniff |
| Referrer-Policy | strict-origin-when-cross-origin |
| Permissions-Policy | camera=(), microphone=(), geolocation=() |
The checker also warns when headers such as Server or X-Powered-By reveal software version numbers.
How the grade works
Each header earns points weighted by its impact: HSTS and CSP count most. A+ needs every important header set correctly; a missing CSP alone usually limits the grade to B.
How to add headers
Set them in your web server (Apache Header set, nginx add_header), your CDN, or your application. Test CSP in report-only mode first so it does not break your site.
Frequently asked questions
Do security headers affect SEO?
Not directly. They protect users, and HTTPS (enforced by HSTS) is a confirmed lightweight ranking signal.
Will adding a Content-Security-Policy break my site?
It can if it is too strict. Start with Content-Security-Policy-Report-Only, review the reports, then enforce it.
Is X-XSS-Protection still needed?
No. Modern browsers removed the XSS auditor, so a Content-Security-Policy is the right protection today.

