Free Security Headers Generator
Learn moreGenerate recommended HTTP security headers (HSTS, X-Frame-Options, Referrer-Policy, and more) with copy‑paste deployment snippets.
Recommended baseline
Strict-Transport-Security (HSTS)
Forces HTTPS for returning visitors. Enable only on HTTPS-only production sites.
SubDomains
Include only if all subdomains support HTTPS.
preload
Only if you plan to submit to the preload list.
X-Content-Type-Options: nosniff
Prevents MIME-type sniffing (safe default).
X-Frame-Options
Protects against clickjacking by controlling if your site can be embedded in an iframe.
Referrer-Policy
Controls how much referrer information is sent on navigation.
Cross-origin hardening (optional)
These can improve isolation, but can break embeds, popups, or loading third-party resources. Enable only if you understand the impact.
Cross-Origin-Opener-Policy
Isolates browsing context (can affect popups and OAuth flows).
Cross-Origin-Resource-Policy
Restricts who can load your resources (images/scripts/fonts).