Free Security Headers Generator

Learn more

Generate recommended HTTP security headers (HSTS, X-Frame-Options, Referrer-Policy, and more) with copy‑paste deployment snippets.

Security Headers
Generate HSTS, X-Frame-Options, Referrer-Policy headers

Recommended baseline

Strict-Transport-Security (HSTS)

Forces HTTPS for returning visitors. Enable only on HTTPS-only production sites.

SubDomains

Include only if all subdomains support HTTPS.

preload

Only if you plan to submit to the preload list.

X-Content-Type-Options: nosniff

Prevents MIME-type sniffing (safe default).

X-Frame-Options

Protects against clickjacking by controlling if your site can be embedded in an iframe.

Referrer-Policy

Controls how much referrer information is sent on navigation.

Cross-origin hardening (optional)

These can improve isolation, but can break embeds, popups, or loading third-party resources. Enable only if you understand the impact.

Cross-Origin-Opener-Policy

Isolates browsing context (can affect popups and OAuth flows).

Cross-Origin-Resource-Policy

Restricts who can load your resources (images/scripts/fonts).

No output generated yet. Use the tool to generate content.