howsafeismyapp

Free tool

nosniff Header Check

X-Content-Type-Options: nosniff tells browsers to trust the content type you declare instead of guessing it. Without it, a guess of "this looks like JavaScript" can turn an uploaded image into executable code. It is a one-line fix; this checks whether you send it.

passive · no signup · nothing stored

What this checks

How the check works

We request your page over HTTPS and inspect the response headers for X-Content-Type-Options: nosniff — the same header every browser receives. Passive, read-only, nothing stored.

Common questions

What does nosniff mean?

It is the only value the X-Content-Type-Options header accepts, and it means: do not sniff. The full header is X-Content-Type-Options: nosniff, and it tells the browser to trust the Content-Type you declared for a file instead of inspecting the bytes and deciding for itself. Written “no-sniff” or “no sniff” it is the same header — the value itself carries no hyphen.

What is MIME sniffing?

When a server labels a file with a content type, browsers historically second-guessed that label by inspecting the bytes. Helpful for broken servers decades ago; today it means a file you serve as an image can be reinterpreted and run as a script.

Why does nosniff matter if my content types are correct?

Because user-uploaded content is where it bites. If visitors can upload files that you serve back, sniffing lets a crafted upload execute inside your origin — stored XSS, with none of your own code at fault.

How do I set it?

Send X-Content-Type-Options: nosniff on every response — one line in vercel.json, a _headers file on Netlify, or your proxy config. There is no downside and nothing to tune.

All free tools · every check explained · run the full 15-point check