SCANTIDE ONLINE
Scantide Online Guide

External Security Header Review: What to Check and Why

Public security headers reveal part of the browser hardening delivered to every visitor. HSTS, CSP, frame controls, MIME handling and referrer policy are useful evidence of configuration quality.

Technical guideUpdated 25 September 2026Scantide Online
Short answer: Public security headers reveal part of the browser hardening delivered to every visitor. HSTS, CSP, frame controls, MIME handling and referrer policy are useful evidence of configuration quality.

Headers are part of the delivered application

A security header configured on the origin may disappear or change at a CDN, proxy or load balancer. External review verifies the actual public response.

Prioritize by function

HSTS, CSP, frame protections, X-Content-Type-Options, Referrer-Policy and Permissions-Policy address different browser behaviors.

Avoid binary thinking

A missing header is not equal to a critical vulnerability. The page purpose, browser behavior and other controls determine importance.

Online gives a public-domain view

Scantide Online reviews security headers together with TLS, DNS, cookies and infrastructure. Observe can complement that with live browser-visible page behavior.

Practical depth: examples, failure modes and what to verify

Source note: current Scantide material describes the present platform. Older JufCorp/Red Cloud material is retained as field experience and historical context. Old product names, versions and configuration examples are not presented as current requirements.

Current Scantide detail

Current Scantide source: Website Security Header Scanner

Scantide Online reviews website security headers such as HSTS, CSP, X-Frame-Options and related browser controls in the context of the public site.

Current Scantide source: Domain Security Scanner for DNS, HTTPS and Web Exposure

Use Scantide Online to check DNS and mail security, HTTPS/TLS, security headers, cookies and public infrastructure context from one domain scan.

Current Scantide source: Public Server Security Assessment

Use Scantide Online to review public hosts, HTTPS, headers, DNS and infrastructure evidence for a readable first-pass public server security assessment.

Current Scantide source: DNS, SPF and DMARC Security Checker

Scantide Online reviews public DNS, mail-security records, HTTP/HTTPS behavior, TLS, security headers, cookies, infrastructure and CVE-related context to provide a readable external assessment of a domain.

Current Scantide source: DNS, SPF and DMARC Security Checker

Scantide Online checks public DNS and mail-security signals including SPF and DMARC as part of a broader external domain assessment.

Field experience from the archive

Historical source · JufCorp: Securing your server environment - Part III - Operating systems

Whatever you'll be using your server for. have a look at any information that it "bleeds". This could for instance be headers telling any attacker exactly what version of software you're running. If possible, try to hide such information. There's no need for it to be visible and help a hacker find a way in. Simple checks using telnet to the ports your services might reveal some interesting information . Sadly, it's not possible to remove all headers etc but you should give it a go and remove as many as possible While on the subject, use SSL-certificates for any service where possible. Also make sure to set it up correctly (disable weak ciphers, enable HSTS, set correct HTTP headers, set TLS correctly etc ) . Have a look at Letsencrypt for instance for SSL certificates. It's free, supported by basically everyone and it'll probably get the job done for you . All you have to remember is to check that your certificates are renewed every three months.

Historical source · JufCorp: Anyone ideas? How to disable vompatibility check in Excel 2007?

Disbling compatibiliy check when opening 2003 .xls in @Office 2007 impossible. Gah. Comp-check f##%s it up in remote app when alt pg up don't work.

Historical source · JufCorp: Security Reality Check: Why a Perfect Score Doesn't Mean You're Safe

This automated scanner focuses on infrastructure vulnerabilities, exposed services, and configuration issues. However, many critical security threats require manual testing, code review, or specialized tools. Ensure your security strategy addresses the following areas:

Historical source · JufCorp: Syspeace first public month - 40 000+ brute force attacks blocked!

So far,our first public month.40 000+ brute force attacks successfully blocked and traced! #rdp #windowsserver #infosec http://t.co/KOlgoMLO -- Syspeace (@Syspeace)

Practical review checklist

Frequently asked questions

Is X-Frame-Options obsolete if CSP is present?

Frame-ancestors in CSP is the modern flexible control, but compatibility and deployment context still matter.

Can a CDN add or remove security headers?

Yes. That is one reason external verification is useful.

Check the evidence with Scantide Online

External domain security, privacy and infrastructure assessment. Scantide is designed to show observable evidence and readable context rather than turn every observation into a vulnerability claim.

Run Scantide OnlineMore guidesAll Scantide guides