X-Content-Type-Options header
The HTTP X-Content-Type-Options response header indicates that the MIME types advertised in the Content-Type headers should be respected and not changed.
The header allows you to avoid MIME type sniffing by specifying that the MIME types are deliberately configured.
Site security testers usually expect this header to be set.
Note:
The X-Content-Type-Options header only apply request-blocking due to nosniff for request destinations of "script" and "style".
| Header type | Response header | 
|---|---|
| Forbidden request header | No | 
Syntax
http
X-Content-Type-Options: nosniff
Directives
- nosniff
- 
Blocks a request if the request destination is of type styleand the MIME type is nottext/css, or of typescriptand the MIME type is not a JavaScript MIME type.
Specifications
| Specification | 
|---|
| Fetch> # x-content-type-options-header> | 
Browser compatibility
Loading…
See also
- Content-Type
- The original definition of X-Content-Type-Options by Microsoft.
- Use HTTP Observatory to test the security configuration of websites (including this header).
- Mitigating MIME Confusion Attacks in Firefox