| Content isolation |
|---|
| Content-Security-Policy | Whitelists the sources the page may load scripts, styles, and frames from. | default-src 'self'; script-src 'self' |
| Content-Security-Policy-Report-Only | Reports violations without blocking; the staging step before enforcing. | default-src 'self'; report-uri /csp |
| CSP sandbox | Applies sandbox restrictions to the whole document, not just an iframe. | Content-Security-Policy: sandbox allow-scripts |
| X-Content-Type-Options | Stops the browser from sniffing a content type other than the declared one. | nosniff |
| Cross-Origin-Opener-Policy | Cuts script access between the page and the cross-origin windows it opens. | same-origin |
| Cross-Origin-Embedder-Policy | Lets the page load only cross-origin resources that opt in through CORP or CORS. | require-corp |
| Cross-Origin-Embedder-Policy: credentialless | Loads no-CORS resources without CORP by stripping credentials from them. | credentialless |
| Cross-Origin-Resource-Policy | Opts a resource out of being embedded by cross-origin pages. | same-origin |
| Framing |
|---|
| X-Frame-Options: DENY | Blocks every site, including the page's own origin, from framing it. | DENY |
| X-Frame-Options: SAMEORIGIN | Allows framing only by pages on the page's own origin. | SAMEORIGIN |
| CSP frame-ancestors | Names the sources that may frame the page; supersedes X-Frame-Options when both are set. | frame-ancestors 'none' |
| X-Frame-Options: ALLOW-FROM | Obsolete; modern browsers ignore it. Use frame-ancestors instead. | ALLOW-FROM https://example.com (ignored) |
| Referrer & permissions |
|---|
| Referrer-Policy | Limits the URL the browser sends as a referrer on outgoing requests. | strict-origin-when-cross-origin |
| Referrer-Policy: no-referrer | Strips the referrer from every outgoing request. | no-referrer |
| Permissions-Policy | Grants or blocks browser features per origin. | camera=(), geolocation=(self) |
| Permissions-Policy delegation | Iframes inherit the policy unless the embedder hands the feature over with the allow attribute. | <iframe allow="camera *"> |
| Transport |
|---|
| Strict-Transport-Security | Forces HTTPS for the host for max-age seconds. | max-age=31536000 |
| HSTS includeSubDomains | Extends the HTTPS rule to every subdomain; breaks subdomains still on plain HTTP. | max-age=31536000; includeSubDomains |
| HSTS preload | Opts the host into the browser preload list, closing the first-visit gap. | max-age=31536000; includeSubDomains; preload |
| HSTS rollback | max-age=0 lifts the policy for browsers; preload removal takes months. | max-age=0 |
| CSP upgrade-insecure-requests | Rewrites every http:// subresource request to https:// before it leaves the page. | upgrade-insecure-requests |