Secure Tengine with security headers

2026-09-29

AdSense Slot

Your site may be functionally perfect and still score badly on security checkers like SecurityHeaders.com or the Mozilla Observatory — usually because of missing HTTP response headers. These headers cost nothing, break nothing for normal visitors, and harden your site against common web attacks. Here is the block I add to every Tengine server.

The header block

server {
    add_header X-Frame-Options SAMEORIGIN always;
    add_header X-Content-Type-Options nosniff always;
    add_header Referrer-Policy strict-origin-when-cross-origin always;
    add_header X-XSS-Protection "1; mode=block" always;
    add_header Permissions-Policy "geolocation=(), microphone=(), camera=()" always;

    add_header Strict-Transport-Security "max-age=31536000; includeSubDomains" always;
}

What each one does:

Two important notes

Verify with curl

curl -I https://yourdomain.com/

You should see all five headers in the response. Then re-run a header checker and watch the score jump.

Summary

Five lines of headers close the most common web-hygiene gaps, and the always keyword plus single-level placement are the two details that make them actually work. Since you are locking things down, my rate limiting guide handles the brute-force side of the same job.

AdSense Slot