Safeguarding your website from online threats is paramount. Security Headers act as a powerful shield, deflecting common cyber attacks. This guide provides a clear and straightforward method to configure these essential headers through Cloudflare, ensuring robust protection for your website.
Activate Cloudflare Proxy
To apply Security Headers on Cloudflare, you need to enable Cloudflare proxy for your domain. Access your Cloudflare account, select the domain, and follow these steps:
- Go to “DNS” > “Records”.
- Enable “CloudFlare Proxy”.
Add Security Headers Rules
- Access “Rules” > “Transform Rules”.
- Choose the tab “Modify Response Header” > “Create rule”.
- Name the rule > Select “All incoming requests”.
- Add the following rules:
content-security-policy
|upgrade-insecure-requests; block-all-mixed-content
permissions-policy
|accelerometer=(), camera=(), geolocation=(), gyroscope=(), magnetometer=(), microphone=(), midi=()
referrer-policy
|no-referrer-when-downgrade
strict-transport-security
|max-age=31536000; includeSubDomains; preload
x-content-type-options
|nosniff
x-frame-options
|SAMEORIGIN
x-xss-protection
|1; mode=block
- Select Deploy
Check the Results
Visit the website //securityheaders.com/ to check the effectiveness of Security Headers. The goal is to achieve an A+ grade.
Configuring Security Headers with Cloudflare helps protect your website against many common cyber attacks. Follow the instructions above to enhance the security of your website.
Leave a Reply
View Comments