Defaults.Exposed

Security headers that do nothing: 205,448 domains send values the browser throws away

In the September 2026 census, 205,448 domains sent at least one security header that the browser reads and then throws away. The header is in the response, and a checklist that looks for its name will tick it. The browser’s own parsing rules discard the value, and the page behaves as if the header had never been sent. For 100,224 of those domains, every one of these headers they send is discarded.

The count covers four headers: X-Frame-Options, X-Content-Type-Options, Referrer-Policy and Strict-Transport-Security. It’s taken over the 125,815,030 graded domains whose home page answered with a 2xx status, because those are the responses where the census reads a page’s own headers. Shares on this page are of that base, or of its part in one group of TLDs (Top-Level Domains) where a table says so, so the 205,448 are 0.16% of it.

Larger groups send values that parse cleanly and still leave a visitor less protected than no header would. 1,173,869 domains set a Referrer-Policy that hands other sites more of the page address than the browser’s own default, and 703,593 send HSTS (HTTP Strict Transport Security) with max-age=0, which tells the browser to forget the site’s HTTPS-only rule. Another 910,011 send HSTS on a plain-HTTP response, where browsers ignore it. These groups can overlap, so they aren’t added together.

Horizontal bars counting domains by the header value they sent. Discarded by the browser: X-Frame-Options ALLOWALL 43,563, ALLOW-FROM 36,694, other X-Frame-Options values 49,355, X-Content-Type-Options other than nosniff 43,877, Referrer-Policy empty or without a policy name 52,058, HSTS without a usable max-age 16,503. Valid and weaker than no header: Referrer-Policy no-referrer-when-downgrade 1,123,509, unsafe-url 50,360, HSTS max-age=0 703,593. Ignored: HSTS on a plain-HTTP response 910,011.

Figure 1. Header values the browser discards, in blue; valid values that leave a visitor less protected than no header, in orange; and HSTS sent where browsers ignore it, in grey. Counted in domains, on one scale.

How the browser decides a value counts

Each of these headers has a written rule for reading its value, and each rule says what happens to a value it doesn’t recognise. In every case the browser ignores it.

For X-Frame-Options, the HTML Standard splits the value on commas, ignores case and repeats, and acts on DENY or SAMEORIGIN. A lone ALLOWALL, any ALLOW-FROM, an empty value or anything else is treated “as if the header were omitted entirely”. Two different values block framing, a deliberate choice for a header that looks confused.

X-Content-Type-Options has one rule in the Fetch Standard: the first value must be nosniff, in any case.

A browser reading Referrer-Policy keeps the last value it recognises as one of the eight policies and skips the rest. With none, it falls back to its default, strict-origin-when-cross-origin.

For Strict-Transport-Security, RFC 6797 (Request for Comments) makes max-age compulsory, allows each directive once, and tells browsers to ignore a header that breaks that syntax. It also tells them to ignore any HSTS header that arrives over plain HTTP (Hypertext Transfer Protocol).

Browsers haven’t always applied these rules the same way. A 2025 study from CISPA ran 177,146 security-header tests across 16 browser configurations and found 5,606 that behaved differently from one browser to the next. Firefox, for one, used to block framing for SAME ORIGIN written with a space, a value Chrome ignored. Every engine departed from the HSTS RFC somewhere, and Chrome rewrote its HSTS parser after the researchers’ reports. Several of those bugs have since been fixed. This count follows the written rules, and a browser that hasn’t taken a fix may still accept a value counted here.

Check your own response first

One request shows all four headers as your server sends them:

curl -sI https://<your-domain> | grep -iE 'x-frame-options|x-content-type-options|referrer-policy|strict-transport-security'

The values that work are short. X-Frame-Options should read DENY or SAMEORIGIN and nothing else, X-Content-Type-Options nosniff, and Referrer-Policy one of the eight policy names, with nothing after the value, not even a semicolon. Strict-Transport-Security should start with max-age= followed by a number of seconds above zero. If a line carries anything else, the sections below say what the browser does with it.

X-Frame-Options: ALLOWALL, ALLOW-FROM and a stray semicolon

129,612 domains send an X-Frame-Options value the browser treats as absent. The commonest is ALLOWALL, a legacy value the standard names only so it can ignore it, which 43,563 domains send on its own or repeated. Then comes ALLOW-FROM, in one form or another, from 36,694 domains. RFC 7034 described ALLOW-FROM in October 2013, and the HTML Standard, which now defines the header, says it’s “not to be implemented”. A site that sends it to let one partner frame its pages has, in practice, let every site do so.

The third large group is a single character. 32,196 domains send SAMEORIGIN;, with a semicolon after the value. To the browser that’s a different string from SAMEORIGIN, so the header is dropped.

A table of six X-Frame-Options cases with what the browser does and the domains sending each: SAMEORIGIN 13,330,179, DENY 4,132,454, two different values 37,610, ALLOWALL 43,563, ALLOW-FROM 36,694, any other value 49,355. The first three work; the last three are treated as if the header were absent.

Figure 2. How the HTML Standard reads X-Frame-Options, with the domains sending each case.

These are the most common discarded strings, with case variants counted together and any web address replaced by <address>:

Value sentDomainsShare of the basis
ALLOWALL42,8300.03%
SAMEORIGIN;32,1960.03%
ALLOW-FROM <address>28,0810.02%
(empty)4,311under 0.01%
ALLOW3,320under 0.01%
ALLOW-FROM *2,712under 0.01%
ALLOW-FROM <address> <address> <address>2,528under 0.01%
“SAMEORIGIN”1,637under 0.01%

Shares are of the 125,815,030 graded domains whose page answered 2xx.

Two groups need no fix. 37,610 domains send two different values, most often DENY, SAMEORIGIN, and the standard blocks framing for them on purpose. And 26,769 of the domains with a discarded X-Frame-Options also send a Content-Security-Policy with a frame-ancestors directive, which takes precedence. For those sites the broken header costs nothing, because the policy does the work. frame-ancestors versus X-Frame-Options covers the difference.

X-Content-Type-Options: one valid value, and the same semicolon

This header has one valid value, and 43,877 domains still send something else first. Most of them send nosniff;, the same stray semicolon. The rest include curly quotes, misspellings and a fragment of a server config line:

Value sentDomainsShare of the basis
nosniff;32,7080.03%
nosniff”3,253under 0.01%
"nosniff" always2,572under 0.01%
DENY, nosniff900under 0.01%
no-sniff687under 0.01%
: nosniff406under 0.01%

Shares are of the 125,815,030 graded domains whose page answered 2xx.

"nosniff" always matches the end of an nginx add_header line, quotes and the always flag included, sent as the value itself. DENY, nosniff puts an X-Frame-Options value in front, and the browser only reads the first.

Referrer-Policy: empty headers, and two policies weaker than none

52,058 domains send a Referrer-Policy the browser can’t use, and 49,968 of them send it empty. The other 2,090 carry text that names no policy, including the placeholders value and policy. The browser falls back to its default for all of them, so the header changes nothing.

Value sentDomainsShare of the basis
(empty)49,9680.04%
value240under 0.01%
SAMEORIGIN159under 0.01%
policy137under 0.01%
“no-referrer-when-downgrade”80under 0.01%

Shares are of the 125,815,030 graded domains whose page answered 2xx.

The larger group sends a valid policy that gives away more than the default would. With no header at all, a browser sends another site only your origin, the https:// and host name. no-referrer-when-downgrade, sent by 1,123,509 domains, sends other HTTPS (Hypertext Transfer Protocol Secure) sites the full address of the page, path and query string included. unsafe-url, sent by 50,360 domains, sends the full address everywhere, plain-HTTP pages too. CISPA found that Brave, Firefox and Safari don’t support unsafe-url, apart from Firefox when a visitor clicks a link and Firefox and Safari between pages of the same site. Chrome applies it.

Horizontal bars counting the domains that send Referrer-Policy by the policy the browser applies: no-referrer 490,820, same-origin 725,369, strict-origin 159,941, strict-origin-when-cross-origin 8,407,859, origin 47,948, origin-when-cross-origin 118,013, no-referrer-when-downgrade 1,123,509, unsafe-url 50,360, empty or no policy name 52,058.

Figure 3. The Referrer-Policy each sender ends up with. Orange bars send the full page address to other sites.

Strict-Transport-Security: a missing max-age, a broken one, and max-age=0

16,503 domains send an HSTS header over HTTPS that RFC 6797 tells the browser to ignore. 8,823 have no max-age directive the browser can find, 6,411 have one with no value or a value that isn’t a whole number of seconds, 24 repeat a directive, and 909 break the syntax somewhere else. The commonest is max-age= with nothing after it:

Value sentDomainsShare of the basis
max-age=4,709under 0.01%
"max-age=31536000; includeSubDomains; preload" always2,492under 0.01%
maL-age=31536000;includeSubDomains;1,842under 0.01%
max-age:31536000; includeSubDomains509under 0.01%
max-age=, max-age=453under 0.01%
(empty)318under 0.01%
Strict-Transport-Security: max-age=31536000;284under 0.01%
Strict-Transport-Security: max-age=31536000; includeSubDomains282under 0.01%

Shares are of the 125,815,030 graded domains whose page answered 2xx.

Further down are the end of an nginx line again, a typed maL-age, a colon where the equals sign goes, and the header’s own name pasted into its value.

max-age=0 is a different case. It’s valid, and the RFC gives it one meaning: the browser must remove the policy it holds for the site. 703,593 domains send it. On a site moving off HTTPS that’s the right instruction, and anywhere else it leaves a returning visitor with no HTTPS-only rule. The 910,011 domains that send HSTS on a plain-HTTP response, because HTTPS failed, get the same result from the other direction: the browser never stores the header at all. The HSTS guide covers the safe order for raising max-age.

One value, one piece of software

The census never names a site, but a response often names the software behind it. X-Powered-By, when it’s sent, names an application framework or platform, and Server names whatever answered the request, which is often a CDN (Content Delivery Network) or proxy in front of the real server. Counted by Server alone, the general-purpose servers carry the most discarded values because they answer for most of the domains counted here: 43,456 domains behind nginx, 40,766 behind Cloudflare and 33,867 behind Apache. The groups where one value comes with one software signature say more.

Horizontal bars for the largest groups of domains sending one header value with one software signature. Strict-Transport-Security max-age=0 with Server squarespace 267,790; max-age=0 with includeSubDomains and preload behind openresty 260,495; Referrer-Policy no-referrer-when-downgrade with Server flywheel 58,312; X-Content-Type-Options nosniff; with no Server or X-Powered-By 30,254; X-Frame-Options SAMEORIGIN; with no Server or X-Powered-By 30,236; ALLOWALL from Next.js behind Cloudflare 15,688; ALLOW-FROM with Server frontend-web 3,327.

Figure 4. The largest groups that send the same value with the same software named. Blue values are discarded; orange values are valid and weaker than no header.

The two biggest are both HSTS max-age=0. 267,790 domains whose Server header reads squarespace send exactly that value, and 260,495 behind openresty send max-age=0; includeSubDomains; preload. Both are valid, and both tell a browser to drop any HTTPS-only rule it holds for the site.

Of the 58,460 domains whose Server header reads flywheel, 58,347 send a Referrer-Policy weaker than the default. Among domains whose X-Powered-By names W3 Total Cache, 3,849 send a Referrer-Policy the browser discards and 11,222 one weaker than the default.

The stray semicolons sit on responses that name no software. 30,236 domains send SAMEORIGIN; and 30,254 send nosniff; with no Server or X-Powered-By header, and 22,600 of the first are under .рф, with 7,206 more under .ru. That pair accounts for most of what sets .рф apart: 8.4% of the .рф domains in the base send a discarded value, and 22,602 send two on the same response.

Of the domains sending ALLOWALL, 16,463 name Next.js in X-Powered-By, more than any other product. And one server that calls itself frontend-web sends ALLOW-FROM with a single partner address on all 3,327 of its domains.

These are adoption counts, and they say nothing about whether the software is safe. A header value set in a template, a platform default or a copied config snippet is served by every site built from it, so one fix upstream can clear a whole bar of Figure 4. What the web announces about itself explains why a Server value is a weak guide to what’s running.

gTLDs and ccTLDs

GroupBasisAny header discardedReferrer-Policy weaker than defaultHSTS max-age=0
gTLDs86,338,0410.12%0.83%0.60%
ccTLDs39,164,6380.19%1.2%0.47%
All TLDs125,815,0300.16%0.93%0.56%

Each row’s shares are of that group’s graded domains whose page answered 2xx. Internationalised TLDs, .рф among them, are in the All TLDs row only.

Paired bars comparing gTLDs and ccTLDs on the share of each group's basis that sends a discarded value: any of the four headers, gTLDs 0.12% and ccTLDs 0.19%; then each header, Referrer-Policy weaker than the default, gTLDs 0.83% and ccTLDs 1.2%, and HSTS max-age=0, gTLDs 0.60% and ccTLDs 0.47%.

Figure 5. Discarded and weakening values as a share of each group’s own basis, gTLDs in blue and ccTLDs in orange.

ccTLD domains send a discarded value more often than gTLD domains, and a weaker Referrer-Policy too. gTLD domains send max-age=0 more often.

What to send instead

Four lines cover it. Set them in one place, the server, the CDN or the framework, and remove any copy set elsewhere:

X-Frame-Options: SAMEORIGIN
X-Content-Type-Options: nosniff
Referrer-Policy: strict-origin-when-cross-origin
Strict-Transport-Security: max-age=31536000; includeSubDomains

Use DENY if no page of yours is ever framed, and add Content-Security-Policy: frame-ancestors 'self', which overrides X-Frame-Options wherever both are sent. If a partner needs to frame a page, name it in frame-ancestors; ALLOW-FROM won’t do it. Send HSTS only once every subdomain answers on HTTPS, and start with a short max-age if you’re unsure. The HTTP headers guide covers each one and the console error you’ll see when it misfires.

How this was counted

The base is the graded domains whose home page answered with a 2xx status and whose headers the census evaluated: 125,815,030. The census publishes 125,815,036 as the base for its X-Frame-Options, X-Content-Type-Options and Referrer-Policy checks. The 6 between them are .us domains scanned twice, where the published figure keeps either scan and this count keeps the later one. Another 1,500 domains answered 2xx without their headers being evaluated, and they’re left out. Redirects the scanner couldn’t follow, error pages and challenge pages are outside the base too, and 88,726 domains sent a discarded value on one of those. The larger count of domains that sent any Server, CSP or X-Powered-By header isn’t used, because it includes those non-page responses.

The headers read are the ones on the HTTPS request for each domain’s home page, after the scanner’s same-site redirects, or on the plain-HTTP request where HTTPS failed. HSTS is read from the domain’s own first response, as the census’s HSTS check reads it. Repeated header lines arrive joined by commas, which both standards read the same way.

The rules applied are the HTML Standard for X-Frame-Options, the Fetch Standard for X-Content-Type-Options, the Referrer Policy specification and RFC 6797, as written in October 2026. Referrer-Policy names are matched without regard to case, as the census matches them. When an HSTS value holds a comma, only the part before it is read.

The census grade’s own X-Content-Type-Options check applies the same rule. Its X-Frame-Options check fails every value counted here as discarded unless the page also carries a restrictive frame-ancestors. Its Referrer-Policy check passes a header that names no policy, so 2,090 of the domains counted here pass it.

Server is cut to its first word and X-Powered-By to its first one or two, as sent. Host names are left out of the rankings, and no site is named.

Figures as of 5 September 2026, from the September 2026 edition of the defaults.exposed census. The specifications and the CISPA study were read on 4 October 2026. Census numbers move every month; the current values are on the data page.