check.uk.app

Security headers: understand the results

Review policy values and missing headers without breaking legitimate site features.

check.uk.app technical team · Reviewed 26 September 2026

Presence is only the first check

check.uk.app records headers in the tested response. Presence does not prove that a policy is effective or applies to every route. Open HTTP headers to review values. Compare the homepage, sign-in and error responses; proxy and application rules may differ.

HTTPS persistence and content types

Strict-Transport-Security makes browsers keep using HTTPS for its configured lifetime. Check HTTPS on every affected subdomain before using includeSubDomains. Start with a short lifetime; removing the header does not immediately undo a cached policy. Preload is a separate decision.

X-Content-Type-Options: nosniff tells browsers to respect the declared content type. Check that JavaScript and CSS have correct MIME types. Fix a wrong Content-Type at its source rather than disabling this protection.

Embedding and referrer data

X-Frame-Options restricts framing; CSP frame-ancestors provides more flexible control over allowed embedding sites. Account for legitimate partner embeds before restricting them.

Referrer-Policy controls how much referring URL information the browser sends. Review flows that depend on referrers and keep secrets out of URLs regardless of the policy.

Introduce CSP in observation mode

Content-Security-Policy-Report-Only observes violations without enforcing that candidate policy. An existing enforced CSP remains active. Browser developer tools show violations; collecting reports on a server requires a reporting endpoint and matching configuration.

Inventory scripts, styles, frames and requests needed for sign-in, CAPTCHA, payments and analytics. Test those journeys before enforcement. Do not copy a strict default-src policy into production just to obtain a green result.

Verify one policy at a time

Capture current headers and browser behaviour, change one policy in staging and repeat the checks. Test successful and error responses through the public proxy, not only at the application. Keep a configuration backup and rollback procedure; cached HSTS needs special care.

This is an interpretation guide, not a universal server configuration or penetration test. Inspect the value behind each finding and test the affected user journey. A homepage scan cannot verify every application feature.

Sources

Check your websiteAll guides

A name for your next idea

Give your website, home server or next project a memorable address: yourname.uk.app. Choose your name and check availability before registering.

Find your name

Partners