Security Headers
X-XSS-Protection check
A retired header. Modern browsers ignore it, and the old filter it switched on could be abused, so it is best set to 0.
Check this on your own domain now. It is free with a DomainGuard account, reads only public records, and gives you a report you can send to whoever runs your website.
What we look at
We read the X-XSS-Protection header.
Why it matters to your business
This one is mostly housekeeping: its presence or absence does not protect visitors today. Content-Security-Policy is the header that does its job now.
How to fix it
- Send X-XSS-Protection: 0, or remove it, and put the effort into a Content-Security-Policy.
If you would rather not touch DNS or server settings yourself, forward this page and your report to whoever manages your website, or ask us to do it.
