Security Headers

Cross-origin policy check

Two headers that isolate your pages from other sites a visitor has open, closing off cross-site data leaks.

Check this on your own domain now. It is free with a DomainGuard account, reads only public records, and gives you a report you can send to whoever runs your website.

What we look at

We read the Cross-Origin-Opener-Policy and Cross-Origin-Resource-Policy headers.

Why it matters to your business

They stop another site in the same browser from reaching into your page's window or pulling in your resources, which blocks a family of side-channel attacks. Lower priority than CSP and HSTS, and cheap to add.

How to fix it

  1. Send Cross-Origin-Opener-Policy: same-origin (or same-origin-allow-popups if you use sign-in popups).
  2. Send Cross-Origin-Resource-Policy: same-site.

If you would rather not touch DNS or server settings yourself, forward this page and your report to whoever manages your website, or ask us to do it.