Security Headers
Cross-origin policy check
Two headers that isolate your pages from other sites a visitor has open, closing off cross-site data leaks.
Check this on your own domain now. It is free with a DomainGuard account, reads only public records, and gives you a report you can send to whoever runs your website.
What we look at
We read the Cross-Origin-Opener-Policy and Cross-Origin-Resource-Policy headers.
Why it matters to your business
They stop another site in the same browser from reaching into your page's window or pulling in your resources, which blocks a family of side-channel attacks. Lower priority than CSP and HSTS, and cheap to add.
How to fix it
- Send Cross-Origin-Opener-Policy: same-origin (or same-origin-allow-popups if you use sign-in popups).
- Send Cross-Origin-Resource-Policy: same-site.
If you would rather not touch DNS or server settings yourself, forward this page and your report to whoever manages your website, or ask us to do it.
