Free tool · Runs in your browser, stores nothing

🛡️ Security Headers Generator

Build HTTP security headers for .htaccess (Apache) or Nginx — tick the headers you want and copy them straight in. Defends against XSS, clickjacking and data interception.

Choose headers

HSTS (Strict-Transport-Security)
Forces the browser to always use HTTPS, preventing man-in-the-middle interception.
X-Frame-Options
Stops your site being embedded in someone else's iframe (clickjacking).
X-Content-Type-Options
Stops the browser MIME-sniffing (nosniff), reducing the risk of malicious files.
Referrer-Policy
Controls how much referrer information is sent to other sites.
Permissions-Policy
Disables APIs you don't use, such as camera, microphone and location.
Content-Security-Policy (basic)Advanced
Restricts where scripts/styles can load from to reduce XSS — start from a basic policy and refine.

Output

Test on a staging site before going live, especially HSTS preload and CSP which can affect rendering.

Security headers every site should have

Adding these headers closes common vulnerabilities without touching your application code — the most cost-effective first line of defence.

HSTS

Forces HTTPS every time. Even if a user types http://, the browser upgrades to https:// automatically, preventing interception.

X-Frame-Options

Prevents your site being embedded in a malicious iframe, blocking clickjacking that tricks users into clicking unknowingly.

Content-Security-Policy

Declares which sources scripts and resources may load from — the strongest shield against XSS.

Referrer & Permissions

Controls data leaked via the referrer and disables unused APIs such as camera and mic, shrinking your attack surface.

Frequently asked questions

1

Why do security headers matter?

They are instructions the server sends the browser to enforce safety rules — forcing HTTPS, blocking framing, and limiting script sources to reduce XSS. They close common vulnerabilities without changing application code.

2

Where do I add security headers on DirectAdmin?

On Apache, place the Header directives in the .htaccess file in your public_html folder. DirectAdmin supports .htaccess directly — create or edit the file and upload it, and the server applies the values immediately without a restart.

3

What is HSTS preload and should I enable it?

It registers your domain in a list baked into browsers, forcing HTTPS from the first visit. Only enable it once every subdomain fully supports HTTPS, because removing a domain from the list is difficult and slow.

4

What happens if my CSP is too strict?

If a CSP restricts script/style sources too tightly, resources your site actually uses (e.g. Google Fonts) can be blocked and the page may break. Start from a basic policy, check the console for blocks, then allow sources one at a time.

AsiaGB Hosting

Hosting with full .htaccess control on DirectAdmin

AsiaGB lets you edit .htaccess and set security headers yourself, with free SSL and a Thai support team helping keep your site secure.

See hosting plans