Learn Website Security
Whether you're locking down your first WordPress site or hardening a fleet of microservices, start here.
Popular guides
Guide
HTTP Security Headers: A Practical Guide
Every HTTP security header explained in plain English, with production-ready examples for Nginx, Apache, Cloudflare, Express and WordPress.
Read
Guide
Content Security Policy (CSP): What It Is and How to Ship It
A step-by-step guide to writing, testing and shipping a strict Content Security Policy without breaking your site.
Read
Guide
HTTP Strict Transport Security (HSTS)
How HSTS works, how to enable it safely, and when (and how) to preload your domain into every major browser.
Read
Guide
Referrer-Policy
Referrer-Policy controls how much of your URL is sent to other sites. Here's the setting that balances analytics with privacy.
Read
Popular tools
Tool
Security Headers Checker
Test HSTS, CSP, X-Frame-Options, Referrer-Policy and Permissions-Policy in seconds.
Read
Tool
SSL Certificate Checker
Verify the SSL certificate for any domain in seconds.
Read
Tool
TLS Checker
Confirm modern TLS support for any hostname.
Read
Tool
Cookie Security Checker
See exactly which cookies a site drops and whether they're safe.
Read
Latest articles
headers
Why Your Website Needs HSTS in 2026
One header, one config line, and downgrade attacks stop reaching your users. If your site doesn't ship HSTS in 2026, you're leaving free security on the table.
Read
headers
How to Roll Out CSP in Report-Only Mode
CSP is one of the most effective XSS defenses ever shipped — and one of the most feared to deploy. Report-only mode turns a scary launch into a boring one.
Read
dns
DMARC in Plain English
SPF, DKIM, DMARC. Three DNS records, one goal: stop other people from sending email as you. Here is what each one actually does.
Read