All questions
Q & A Security · September 11, 2026

Will CSP break my site?

Almost certainly, on first deployment. Every third-party script, style, image, or font hosted on a domain not listed in your CSP will be blocked. Deploy CSP in Report-Only mode first (Content-Security-Policy-Report-Only header) for at least a week. Review violation reports, add legitimate sources to the policy, remove or self-host the rest. Only then flip to enforcing Content-Security-Policy.

Read the full guide
HTTP Security Headers Explained: HSTS, CSP, X-Frame-Options, and the Rest
HTTP security headers are the browser-enforced defence layer that runs before your application code. Deployed correctly, they eliminate whole classes of attacks — even when the underlying application has bugs. Deployed incorrectly, they silently break the site.