Skip to main content

Headers

X-Content-Type-Options: nosniff. The one-line defensive header.

Published 2026-06-16 · Last updated 2026-06-16 · Vantyris editorial

X-Content-Type-Options is the smallest entry in the defensive header set: one response header with one allowed value (nosniff). It tells the browser to trust the Content-Type your server declares instead of sniffing the file's contents to guess what it is. Without it, a server that mistakenly returns a .txt file as text/html (or worse, a JSON endpoint an attacker can squeeze HTML into) can end up running it as a script. With it, the browser refuses. It's not the most exciting fix, but it's the cheapest.

What this means for your business

How to fix

Add a single header to every response: X-Content-Type-Options: nosniff. Most web hosts have a 'security headers' setting that includes it as a default.

  1. Check whether the header is already set. Open DevTools → Network, click any request to your site and look at Response Headers for x-content-type-options: nosniff. If it's there, you're done. If not, add it.
  2. Add it at your web host or CDN. Apache: Header always set X-Content-Type-Options nosniff. Nginx: add_header X-Content-Type-Options nosniff always;. Next.js: in the headers function in next.config.mjs. Cloudflare: Rules → Transform Rules → Modify Response Header → add the header.
  3. Verify in DevTools after deploy. Reload and check Response Headers again. The header should now appear.

Owner: Your web host or developer. · Time: 5 minutes.

Common gotchas

How to verify the fix

A Vantyris verified scan checks for the header in the Web hygiene category. securityheaders.com grades the full defensive header set.

Cyber Essentials alignment

This finding informs the following Cyber Essentials control areas (the UK government's baseline scheme, a sound checklist in any country):

Vantyris is not a CE certifying body. The mapping above is informational.

Common follow-up questions

Does nosniff affect search engine crawling?

No. Search crawlers respect Content-Type headers anyway and don't sniff, so in practice the header is invisible to them.

Are there any modern attacks that nosniff actually blocks?

Yes. File-upload XSS is the main one. An attacker uploads a 'png' file that's really HTML, and your site serves it back with the original Content-Type or a generic one. Without nosniff, the browser might render it as HTML and run the embedded scripts. With nosniff, it refuses.

Should I also set X-Download-Options?

That's an old IE-specific header, effectively defunct. Modern security cheatsheets dropped it years ago. Don't bother.

References

Related explainers

Want Vantyris to check your domain for this and 196 other problems?

The teaser scan is free and needs no card. A verified scan starts at $10€10£10A$15¥1,500AED 40 and comes with the workspace: finding workflow, score trend, three PDF layouts, share links and monitoring.

Written by Vantyris