Security headers: which ones matter and what to set them to
Six headers, most of them one line each. They will not fix a vulnerability, but several of them turn one into a non-event.
HTTPS encrypts traffic using a TLS certificate that proves domain ownership. Certificates are issued free and automatically by ACME providers such as Let's Encrypt, typically valid for 90 days and renewed by automation. The practical work is ensuring renewal actually runs, redirecting HTTP to HTTPS, enabling HSTS, and eliminating mixed content.
A certificate binds your domain name to a public key and is signed by a certificate authority the browser trusts. During the handshake, the server proves it holds the matching private key, the two sides agree on session keys, and everything after that is encrypted. TLS 1.3 completes this in a single round trip, and resumed sessions can skip even that.
| Type | Validates | Use |
|---|---|---|
| DV (domain validated) | Control of the domain | Almost everything; free and automatic |
| OV (organisation validated) | Domain plus company identity | Corporate policy requirements |
| EV (extended validation) | Extensive company verification | Rare; browsers no longer show special UI |
| Wildcard | *.example.com | Many subdomains under one certificate |
For the overwhelming majority of sites, a free DV certificate provides identical encryption to a paid one. Paid certificates buy warranties and organisational validation, not stronger cryptography.
Strict-Transport-Security: max-age=31536000; includeSubDomains; preloadAn HTTPS page loading an HTTP subresource. Browsers block active mixed content — scripts, stylesheets, iframes — outright, and flag or upgrade passive content like images. The result is broken functionality that only appears in production.
Monitor certificate expiry externally, alert at 21 days remaining, and test the renewal path — a dry run in staging is worth more than trusting that a cron job from two years ago still works.
Maximum certificate lifetimes are being reduced substantially across the industry, moving towards renewal measured in weeks rather than months. The practical implication is unambiguous: any process that requires a human to renew a certificate needs to be replaced with automation now, not when it next expires.
No. Free DV certificates from ACME providers give identical encryption. Pay only if you specifically need organisation validation or a vendor warranty.
Yes — it is a confirmed, if lightweight, ranking signal, and browsers mark HTTP pages as not secure, which affects trust and conversion far more than the ranking factor does.
One covering all subdomains at a single level. Convenient, but a compromise exposes every subdomain, and it requires DNS-based validation to issue.
Negligibly, and it is a prerequisite for HTTP/2 and HTTP/3, which are meaningfully faster. Net effect on a modern stack is positive.
ROVQIX Engineering
Engineering team, ROVQIX
The ROVQIX engineering team builds and maintains web platforms, APIs and infrastructure for clients across SaaS, ecommerce and enterprise. These notes come out of real production work — deploys, incidents, migrations and audits.
ROVQIXdesigns and builds production web platforms — Next.js front ends, Node.js APIs and the infrastructure behind them. Tell us what you're building and we'll scope it with you.
Six headers, most of them one line each. They will not fix a vulnerability, but several of them turn one into a non-event.
DNS is the layer everyone touches twice a year and nobody remembers. It is also the fastest way to take a site offline for 24 hours.
Not a compliance document. This is the list we actually work through before a client site handles its first real user.
No spam. Just the occasional case study and craft breakdown.