Skip to content

HTTP security configuration

What is X-Content-Type-Options?

Whether responses carry X-Content-Type-Options: nosniff, which stops browsers guessing a file type and running it as something else.

Part of the External Security Check. Free during the preview.

What it checks

Whether responses carry X-Content-Type-Options: nosniff, which stops browsers guessing a file type and running it as something else.

A pass means: Browsers are told not to guess content types.

Possible findings

X-Content-Type-Options is not set

Severity: LowConfidence: ConfirmedKind: Recommended hardening

What we found

Responses do not include X-Content-Type-Options: nosniff.

Why it matters

Without it, browsers may guess a file's type and run content as script that was meant to be plain text or an image.

How to fix it

Add X-Content-Type-Options: nosniff to all responses.

References