HTTP security headers: which ones to set on any website and what each does
What HSTS, Content-Security-Policy, X-Content-Type-Options, X-Frame-Options, Referrer-Policy and Permissions-Policy do, with recommended values and checks.
Category
Behind any website or application there is an infrastructure worth understanding: domains and DNS, hosting, certificates, security headers, backups. In this category we explain those pieces so you can make informed decisions.
Articles focus on concepts and on how to check things yourself, not on commercial recommendations.
What HSTS, Content-Security-Policy, X-Content-Type-Options, X-Frame-Options, Referrer-Policy and Permissions-Policy do, with recommended values and checks.
Anatomy of a JSON Web Token (header, payload and signature), which claims it carries, how to read it, the common security mistakes and where to store it.
How DNS turns a domain into an IP address, what each record type does, what TTL and “propagation” are, and how to check your domain’s configuration with dig.