🛡️
Hosting

Most sites are attacked through basic holes that a few lines in .htaccess can close — namely HTTP security headers, the instructions a server sends the browser to enforce safety rules: always use HTTPS, never allow framing by others, and restrict script sources. This article explains the key headers and how to add them on DirectAdmin.

In short: security headers are the most cost-effective first line of defence because they close common holes without touching application code. Setup takes a few minutes in .htaccess and applies instantly to every page.

What are security headers?

When a browser requests a page, the server returns HTTP response headers with the content. Security headers are a group of these that tell the browser how to enforce safety rules — use HTTPS only, do not render the page in an iframe, or which sources may load scripts. Every modern browser understands and enforces them automatically.

The key headers to have

HeaderProtects againstRecommended value
Strict-Transport-Security (HSTS)Forces HTTPS, stops interceptionmax-age=31536000; includeSubDomains
X-Frame-OptionsClickjacking (iframe embedding)SAMEORIGIN
X-Content-Type-OptionsMIME sniffingnosniff
Referrer-PolicyReferrer leakagestrict-origin-when-cross-origin
Content-Security-Policy (CSP)XSS, malicious script injectionDefine allowed sources (see below)

Add security headers in .htaccess

On Apache/LiteSpeed hosting (including DirectAdmin), add this block to the .htaccess in your site’s public_html folder:

<IfModule mod_headers.c>
  Header always set Strict-Transport-Security "max-age=31536000; includeSubDomains"
  Header always set X-Frame-Options "SAMEORIGIN"
  Header always set X-Content-Type-Options "nosniff"
  Header always set Referrer-Policy "strict-origin-when-cross-origin"
  Header always set Permissions-Policy "geolocation=(), camera=(), microphone=()"
</IfModule>

Save it and the server applies the values immediately without a restart, because .htaccess is read on every request. To build a custom set you can copy and paste, try the AsiaGB Security Headers Generator, which produces the directives for .htaccess or Nginx automatically.

Mind HSTS: once enabled, browsers remember to use HTTPS only for the max-age period. If your SSL isn’t ready on every subdomain, don’t add includeSubDomains or preload yet — they’re hard and slow to undo.

Use Content-Security-Policy correctly

CSP is the most powerful header for reducing XSS because it declares which sources the browser may load scripts, styles and resources from. Externally injected, unauthorised scripts are blocked. A basic policy:

Header always set Content-Security-Policy "default-src 'self'; img-src 'self' data: https:; style-src 'self' 'unsafe-inline'; script-src 'self'; object-src 'none'; frame-ancestors 'self'; base-uri 'self'"

Start from a basic policy and refine, because an overly strict one can block resources your site really uses, such as Google Fonts or analytics, and break the page. To tune it, open the browser console, see what is blocked, then allow sources one at a time.

Verify the headers work

After adding headers, confirm they are actually sent:

Why even ordinary sites should set security headers

Many assume security headers are only for big or banking sites, but in reality small and ordinary business sites are targeted more often because they usually lack basic protection. Automated bots scan for sites missing these headers to find an opening — framing the site to trick clicks, or injecting scripts through an XSS hole. Adding a few header lines is the most cost-effective risk reduction relative to the time spent.

Beyond security, some headers indirectly help trust and SEO. Forcing HTTPS with HSTS means users never hit a "not secure" warning, and Google already uses HTTPS as a ranking signal. A site with complete security settings looks more professional and reassures visitors.

A beginner's order for adding headers

If you're just starting, don't add every header at once. Go step by step to reduce the risk of breaking the site:

  1. Begin with X-Content-Type-Options and X-Frame-Options — the safest, with almost no side effects on ordinary sites.
  2. Add Referrer-Policy and Strict-Transport-Security once your SSL works on every page (no preload yet).
  3. Add Content-Security-Policy last, since it must be tuned to the external scripts your site actually uses — start loose and tighten.
  4. Each time you add a header, test the site immediately and watch the console for anything blocked.

Going step by step makes it easy to identify which header caused a problem; if the site misbehaves after adding one, you can revert just that one without affecting the others already set correctly.

Common mistakes

Summary: a few lines of security headers in .htaccess close many common holes without touching app code. Start with HSTS, X-Frame-Options, X-Content-Type-Options and Referrer-Policy, then add CSP when ready.

Frequently Asked Questions

Where do I put security headers on DirectAdmin?

In the .htaccess file in your site's public_html folder. DirectAdmin supports .htaccess directly; once saved it takes effect immediately without a server restart.

Can CSP break my site?

Yes if it's too strict and blocks external resources your site actually uses, like Google Fonts or analytics. Start from a basic policy, watch the console for blocks, then allow sources one at a time.

Should I enable HSTS preload right away?

No, don't rush. Enable preload only once you're sure every subdomain supports HTTPS, because removing your domain from the browser preload list is difficult and slow.

How can I verify the headers actually work?

Check DevTools Network tab under Response Headers, run curl -I, or use an online security-header checker that grades your site and lists missing headers.

Hosting where you control .htaccess and security yourself

AsiaGB Hosting lets you edit .htaccess and set security headers yourself in DirectAdmin, with free SSL — from 500 THB/year and a Thai support team.

See hosting plans

View all cheap Thailand web hosting plans →