Back to guides

Security Headers: The Response Headers Search Engines and Users Both See

HSTS, CSP, X-Frame-Options and the rest. What each response header protects against, why search visibility depends on it, and how to add them in one place.

Security headers are a small set of response-header directives that decide what a browser will allow on your pages. They cost nothing to add, apply site-wide, and are visible to anyone who inspects a response, including the people evaluating whether your site is trustworthy. Their value is concrete. HSTS removes the plaintext first request that makes downgrade attacks possible. A Content-Security-Policy limits which origins may execute scripts, containing an injected script rather than letting it read every page it lands on. X-Frame-Options and frame-ancestors stop your pages being framed by a site that overlays its own controls on yours. X-Content-Type-Options stops a browser guessing that an uploaded file is executable JavaScript. Referrer-Policy and Permissions-Policy control what leaves the page: which URLs travel in the Referer header, and which device APIs embedded content may request. The search connection is indirect and real. A site compromised through an injected script starts serving pages that are not yours, and search engines act on that quickly, first with warnings in results and then with removal. Recovery takes far longer than the configuration would have. You can confirm what you serve by reading the response headers on your own pages, which is what a browser, a crawler or a security reviewer sees first. Most sites can add every one of them in a single change at the edge.

SEOReport's paid diagnosis reviews this across the pages of your own site, shows the evidence behind every finding, and ranks the fixes by priority. See plans and pricing.

Get the complete diagnosis of your site

An evidence-backed report and a prioritized action plan, on a plan with monthly credits.