Free tool
nosniff Header Check
X-Content-Type-Options: nosniff tells browsers to trust the content type you declare instead of guessing it. Without it, a guess of "this looks like JavaScript" can turn an uploaded image into executable code. It is a one-line fix; this checks whether you send it.
What this checks
- ✓No nosniff header Security header
How the check works
We request your page over HTTPS and inspect the response headers for X-Content-Type-Options: nosniff — the same header every browser receives. Passive, read-only, nothing stored.
Common questions
What does nosniff mean?
It is the only value the X-Content-Type-Options header accepts, and it means: do not sniff. The full header is X-Content-Type-Options: nosniff, and it tells the browser to trust the Content-Type you declared for a file instead of inspecting the bytes and deciding for itself. Written “no-sniff” or “no sniff” it is the same header — the value itself carries no hyphen.
What is MIME sniffing?
When a server labels a file with a content type, browsers historically second-guessed that label by inspecting the bytes. Helpful for broken servers decades ago; today it means a file you serve as an image can be reinterpreted and run as a script.
Why does nosniff matter if my content types are correct?
Because user-uploaded content is where it bites. If visitors can upload files that you serve back, sniffing lets a crafted upload execute inside your origin — stored XSS, with none of your own code at fault.
How do I set it?
Send X-Content-Type-Options: nosniff on every response — one line in vercel.json, a _headers file on Netlify, or your proxy config. There is no downside and nothing to tune.
All free tools · every check explained · run the full 15-point check