Security Headers Generator
Create CSP, HSTS, Referrer-Policy, Permissions-Policy and other headers for Nginx, Apache, IIS or Netlify.
These headers are a starting point, not a guarantee of security. Test them with your site before deploying.
Protect your site in the browser
HTTP security headers tell the browser how your site should behave, making attacks such as XSS, clickjacking, protocol downgrades and data leaks harder. They're also among the first things checked in security audits and penetration tests.
Generated headers
- Content-Security-Policy (CSP)
- Strict-Transport-Security (HSTS)
- X-Frame-Options and frame-ancestors
- X-Content-Type-Options
- Referrer-Policy and Permissions-Policy
Ready-made config per server
Your choices are turned into copy-ready configuration for Nginx, Apache (.htaccess), IIS (web.config) and Netlify. Notes explain trade-offs such as CSP Report-Only mode and HSTS preload requirements. Always test before deploying.
How to use Security Headers Generator
- Choose the security headers to enable.
- Adjust CSP sources and the HSTS duration for your site.
- Pick your server type and copy the configuration.
- Test in a staging environment, then deploy.
Why use this tool?
Get configuration for your server in minutes instead of researching each header's syntax.
FAQ
Will these headers make my site secure?
They add important layers of protection, but no set of headers gives complete security for every site. Adjust the sources for your site and test thoroughly.
Can CSP break my site?
Yes, missing source permissions can block scripts and styles. Test with Content-Security-Policy-Report-Only first.
What is HSTS preload?
Adding your domain to the HTTPS list built into browsers. It's hard to undo, so make sure all subdomains support HTTPS.
Related tools
Cache-Control Header Generator
Create the right Cache-Control header with presets for static files, HTML pages and private data.
Open toolNginx Redirect Generator
Create Nginx 301/302 page redirects plus HTTP → HTTPS and www / non-www rules.
Open tool.htaccess Redirect Generator
Create Apache .htaccess page-level 301/302 rules plus HTTP → HTTPS and www / non-www redirects.
Open toolRobots.txt Generator
Create a robots.txt file with Allow, Disallow and sitemap rules for search engine bots.
Open tool