Most sites are attacked through basic holes that a few lines in .htaccess can close — namely HTTP security headers, the instructions a server sends the browser to enforce safety rules: always use HTTPS, never allow framing by others, and restrict script sources. This article explains the key headers and how to add them on DirectAdmin.
In short: security headers are the most cost-effective first line of defence because they close common holes without touching application code. Setup takes a few minutes in .htaccess and applies instantly to every page.
What are security headers?
When a browser requests a page, the server returns HTTP response headers with the content. Security headers are a group of these that tell the browser how to enforce safety rules — use HTTPS only, do not render the page in an iframe, or which sources may load scripts. Every modern browser understands and enforces them automatically.
The key headers to have
| Header | Protects against | Recommended value |
|---|---|---|
| Strict-Transport-Security (HSTS) | Forces HTTPS, stops interception | max-age=31536000; includeSubDomains |
| X-Frame-Options | Clickjacking (iframe embedding) | SAMEORIGIN |
| X-Content-Type-Options | MIME sniffing | nosniff |
| Referrer-Policy | Referrer leakage | strict-origin-when-cross-origin |
| Content-Security-Policy (CSP) | XSS, malicious script injection | Define allowed sources (see below) |
Add security headers in .htaccess
On Apache/LiteSpeed hosting (including DirectAdmin), add this block to the .htaccess in your site’s public_html folder:
<IfModule mod_headers.c> Header always set Strict-Transport-Security "max-age=31536000; includeSubDomains" Header always set X-Frame-Options "SAMEORIGIN" Header always set X-Content-Type-Options "nosniff" Header always set Referrer-Policy "strict-origin-when-cross-origin" Header always set Permissions-Policy "geolocation=(), camera=(), microphone=()" </IfModule>
Save it and the server applies the values immediately without a restart, because .htaccess is read on every request. To build a custom set you can copy and paste, try the AsiaGB Security Headers Generator, which produces the directives for .htaccess or Nginx automatically.
Mind HSTS: once enabled, browsers remember to use HTTPS only for the max-age period. If your SSL isn’t ready on every subdomain, don’t add includeSubDomains or preload yet — they’re hard and slow to undo.
Use Content-Security-Policy correctly
CSP is the most powerful header for reducing XSS because it declares which sources the browser may load scripts, styles and resources from. Externally injected, unauthorised scripts are blocked. A basic policy:
Header always set Content-Security-Policy "default-src 'self'; img-src 'self' data: https:; style-src 'self' 'unsafe-inline'; script-src 'self'; object-src 'none'; frame-ancestors 'self'; base-uri 'self'"
Start from a basic policy and refine, because an overly strict one can block resources your site really uses, such as Google Fonts or analytics, and break the page. To tune it, open the browser console, see what is blocked, then allow sources one at a time.
Verify the headers work
After adding headers, confirm they are actually sent:
- Open browser DevTools (F12), go to the Network tab, click the page request and look at Response Headers.
- Use an online security-header checker to see your score and what’s missing — for example the dnsxray.com Security Headers checker, which grades your site and lists which headers to add.
- Run
curl -I https://yourdomain.comto see all headers the server sends.
Why even ordinary sites should set security headers
Many assume security headers are only for big or banking sites, but in reality small and ordinary business sites are targeted more often because they usually lack basic protection. Automated bots scan for sites missing these headers to find an opening — framing the site to trick clicks, or injecting scripts through an XSS hole. Adding a few header lines is the most cost-effective risk reduction relative to the time spent.
Beyond security, some headers indirectly help trust and SEO. Forcing HTTPS with HSTS means users never hit a "not secure" warning, and Google already uses HTTPS as a ranking signal. A site with complete security settings looks more professional and reassures visitors.
A beginner's order for adding headers
If you're just starting, don't add every header at once. Go step by step to reduce the risk of breaking the site:
- Begin with X-Content-Type-Options and X-Frame-Options — the safest, with almost no side effects on ordinary sites.
- Add Referrer-Policy and Strict-Transport-Security once your SSL works on every page (no preload yet).
- Add Content-Security-Policy last, since it must be tuned to the external scripts your site actually uses — start loose and tighten.
- Each time you add a header, test the site immediately and watch the console for anything blocked.
Going step by step makes it easy to identify which header caused a problem; if the site misbehaves after adding one, you can revert just that one without affecting the others already set correctly.
Common mistakes
- Duplicate headers — if both .htaccess and an app (e.g. a WordPress plugin) set the same header, they may duplicate or conflict. Set each in one place only.
- CSP so strict it breaks the site — start loose and tighten; don’t jump to
script-src 'self'if your site uses external scripts. - Enabling HSTS preload too early — preload suits only sites with HTTPS fully ready on every subdomain.
Summary: a few lines of security headers in .htaccess close many common holes without touching app code. Start with HSTS, X-Frame-Options, X-Content-Type-Options and Referrer-Policy, then add CSP when ready.
Frequently Asked Questions
Where do I put security headers on DirectAdmin?
In the .htaccess file in your site's public_html folder. DirectAdmin supports .htaccess directly; once saved it takes effect immediately without a server restart.
Can CSP break my site?
Yes if it's too strict and blocks external resources your site actually uses, like Google Fonts or analytics. Start from a basic policy, watch the console for blocks, then allow sources one at a time.
Should I enable HSTS preload right away?
No, don't rush. Enable preload only once you're sure every subdomain supports HTTPS, because removing your domain from the browser preload list is difficult and slow.
How can I verify the headers actually work?
Check DevTools Network tab under Response Headers, run curl -I, or use an online security-header checker that grades your site and lists missing headers.
Hosting where you control .htaccess and security yourself
AsiaGB Hosting lets you edit .htaccess and set security headers yourself in DirectAdmin, with free SSL — from 500 THB/year and a Thai support team.
See hosting plans