Security Headers

Content-Security-Policy check

CSP tells browsers which scripts your site is allowed to run, which stops most injected code from running on your visitors.

Check this on your own domain now. It is free with a DomainGuard account, reads only public records, and gives you a report you can send to whoever runs your website.

What we look at

We read the Content-Security-Policy header your homepage sends.

Why it matters to your business

If an attacker gets a script onto your site (through a plugin flaw or a compromised ad), CSP is what stops it running in your visitors' browsers and stealing card numbers or logins. It is the most powerful of the security headers and the one most sites are missing.

How to fix it

  1. Start with Content-Security-Policy-Report-Only to see what your site loads without breaking anything.
  2. Build an allowlist of the domains your scripts, styles and images come from, then switch to enforcing.

If you would rather not touch DNS or server settings yourself, forward this page and your report to whoever manages your website, or ask us to do it.

Keep an eye on it

A one-off check tells you how things stand today. On Starter and up, DomainGuard re-checks the domains it watches every day and alerts you in the app when something important changes, so you hear about it before a customer does.