Learn Website Security
Whether you're locking down your first WordPress site or hardening a fleet of microservices, start here.
Popular guides
Guide
HTTP Security Headers: A Practical Guide
Every HTTP security header explained in plain English, with production-ready examples for Nginx, Apache, Cloudflare, Express and WordPress.
Read
Guide
Content Security Policy (CSP): What It Is and How to Ship It
A step-by-step guide to writing, testing and shipping a strict Content Security Policy without breaking your site.
Read
Guide
HTTP Strict Transport Security (HSTS)
How HSTS works, how to enable it safely, and when (and how) to preload your domain into every major browser.
Read
Guide
Referrer-Policy
Referrer-Policy controls how much of your URL is sent to other sites. Here's the setting that balances analytics with privacy.
Read
Latest articles
headers
Why Your Website Needs HSTS in 2026
One header, one config line, and downgrade attacks stop reaching your users. If your site doesn't ship HSTS in 2026, you're leaving free security on the table.
Read
headers
How to Roll Out CSP in Report-Only Mode
CSP is one of the most effective XSS defenses ever shipped — and one of the most feared to deploy. Report-only mode turns a scary launch into a boring one.
Read
dns
DMARC in Plain English
SPF, DKIM, DMARC. Three DNS records, one goal: stop other people from sending email as you. Here is what each one actually does.
Read