Security Headers
Content-Security-Policy check
CSP tells browsers which scripts your site is allowed to run, which stops most injected code from running on your visitors.
Check this on your own domain now. It is free with a DomainGuard account, reads only public records, and gives you a report you can send to whoever runs your website.
What we look at
We read the Content-Security-Policy header your homepage sends.
Why it matters to your business
If an attacker gets a script onto your site (through a plugin flaw or a compromised ad), CSP is what stops it running in your visitors' browsers and stealing card numbers or logins. It is the most powerful of the security headers and the one most sites are missing.
How to fix it
- Start with Content-Security-Policy-Report-Only to see what your site loads without breaking anything.
- Build an allowlist of the domains your scripts, styles and images come from, then switch to enforcing.
If you would rather not touch DNS or server settings yourself, forward this page and your report to whoever manages your website, or ask us to do it.
Keep an eye on it
A one-off check tells you how things stand today. On Starter and up, DomainGuard re-checks the domains it watches every day and alerts you in the app when something important changes, so you hear about it before a customer does.
