Headers
X-Content-Type-Options: nosniff. The one-line defensive header.
Published 2026-06-16 · Last updated 2026-06-16 · Vantyris editorial
X-Content-Type-Options is the smallest entry in the defensive header set: one response header with one allowed value (nosniff). It tells the browser to trust the Content-Type your server declares instead of sniffing the file's contents to guess what it is. Without it, a server that mistakenly returns a .txt file as text/html (or worse, a JSON endpoint an attacker can squeeze HTML into) can end up running it as a script. With it, the browser refuses. It's not the most exciting fix, but it's the cheapest.
What this means for your business
- Browsers used to 'sniff' a file's actual content whenever the server's declared
Content-Typelooked wrong or generic. That helped badly configured servers, and it also gave attackers an opening. An attacker who could upload a file containing HTML to a site that served it back with a genericContent-Typecould get the browser to render it as HTML and run its scripts. X-Content-Type-Options: nosnifftells the browser to take the declaredContent-Typeat its word. A file the server says isimage/pngloads as an image. If it happens to contain HTML, the browser ignores that and renders nothing.- Modern browsers sniff less aggressively than they used to, but an explicit
nosniffis still the recommended security baseline. It costs nothing and shouldn't break anything that wasn't already broken.
How to fix
Add a single header to every response: X-Content-Type-Options: nosniff. Most web hosts have a 'security headers' setting that includes it as a default.
- Check whether the header is already set. Open DevTools → Network, click any request to your site and look at Response Headers for
x-content-type-options: nosniff. If it's there, you're done. If not, add it. - Add it at your web host or CDN. Apache:
Header always set X-Content-Type-Options nosniff. Nginx:add_header X-Content-Type-Options nosniff always;. Next.js: in the headers function innext.config.mjs. Cloudflare: Rules → Transform Rules → Modify Response Header → add the header. - Verify in DevTools after deploy. Reload and check Response Headers again. The header should now appear.
Owner: Your web host or developer. · Time: 5 minutes.
Common gotchas
- If your site serves user-uploaded files (avatars, document uploads, etc.) with a
Content-Typethe browser doesn't recognise,nosniffmakes the browser download them instead of trying to render them. That's usually what you want for security, though it can surprise users expecting a preview. - If you also serve a separate static-asset domain (
cdn.yourdomain.com), add the header there too. Headers don't carry across origins. - Some legacy IE-targeted code relied on MIME sniffing to render content. If your site has a 2010-era jQuery plugin doing weird things with iframe contentTypes, test before assuming
nosniffis safe. Almost no modern site has this problem.
How to verify the fix
A Vantyris verified scan checks for the header in the Web hygiene category. securityheaders.com grades the full defensive header set.
Cyber Essentials alignment
This finding informs the following Cyber Essentials control areas (the UK government's baseline scheme, a sound checklist in any country):
- A2. Secure configuration: devices and services hardened against the weaknesses they ship with by default.
Vantyris is not a CE certifying body. The mapping above is informational.
Common follow-up questions
Does nosniff affect search engine crawling?
No. Search crawlers respect Content-Type headers anyway and don't sniff, so in practice the header is invisible to them.
Are there any modern attacks that nosniff actually blocks?
Yes. File-upload XSS is the main one. An attacker uploads a 'png' file that's really HTML, and your site serves it back with the original Content-Type or a generic one. Without nosniff, the browser might render it as HTML and run the embedded scripts. With nosniff, it refuses.
Should I also set X-Download-Options?
That's an old IE-specific header, effectively defunct. Modern security cheatsheets dropped it years ago. Don't bother.
References
Related explainers
- Content Security Policy: the header that stops most XSS attacks dead.
- X-Frame-Options and frame-ancestors: the anti-clickjacking header.
- SameSite + Secure cookies: the two attributes every session cookie needs.
Want Vantyris to check your domain for this and 196 other problems?
The teaser scan is free and needs no card. A verified scan starts at $10€10£10A$15¥1,500AED 40 and comes with the workspace: finding workflow, score trend, three PDF layouts, share links and monitoring.
Written by Vantyris