← All headersResponse header

What is an X-Content-Type-Options header?

Set to nosniff to stop the browser guessing a response's content type instead of trusting Content-Type.

X-Content-Type-Options: nosniff is a small header that closes a real security gap - without it, some browsers will try to guess a response's actual content type by sniffing the body, which an attacker can abuse to get a file that's supposedly an image treated as executable script instead. It costs nothing to set correctly on every response, which is why its absence on a website is usually just an oversight rather than a deliberate choice.

Common use case

A file upload service sets X-Content-Type-Options: nosniff on every uploaded file it serves back, preventing a maliciously crafted "image" that actually contains executable script from being sniffed and run as such by the browser.

Example

X-Content-Type-Options: nosniff

History

Introduced by Microsoft in Internet Explorer 8 (2009), later adopted universally and documented alongside X-Frame-Options in the informational RFC 7034 (2013).

Did you know?

It only has one valid value - nosniff - making it one of the simplest headers to get right in this entire reference, and one of the cheapest security wins a site can add.