Cookie Security

Cookie security flags check

Secure, HttpOnly and SameSite are three flags that keep your site's cookies from being stolen or misused.

Check this on your own domain now. It is free with a DomainGuard account, reads only public records, and gives you a report you can send to whoever runs your website.

What we look at

We read the cookies your homepage sets and check each for the Secure, HttpOnly and SameSite flags. HttpOnly is only asked of cookies that look like a session or login; a cart or preference cookie your own scripts read is expected to go without it.

Why it matters to your business

Cookies are what keep people signed in. Without Secure they can travel unencrypted; without HttpOnly a malicious script can read them; without SameSite another site can make requests as your signed-in visitor. A stolen session cookie is as good as a stolen password.

How to fix it

  1. Set Secure and HttpOnly on every session and login cookie.
  2. Set SameSite=Lax (or Strict) unless a cookie genuinely needs cross-site use.
  3. In most CMSs and frameworks these are one setting; ask your developer or host.

If you would rather not touch DNS or server settings yourself, forward this page and your report to whoever manages your website, or ask us to do it.