security / security headers / x-content-type-options
Security headers

X-Content-Type-Options

This header stops browsers from guessing the type of a file, closing a trick attackers use to make harmless-looking files run as code.

Severity if missing
Medium
Category
Security headers
Standard
Fetch / WHATWG

What it is

Browsers sometimes try to guess the real type of a file if the server's declared type looks wrong — a process called MIME sniffing. The X-Content-Type-Options header with the value nosniff tells the browser to stop guessing and trust the declared type exactly.

It's a small, one-line header with no downside, and it removes a whole category of confusion-based attacks.

Why it matters

MIME sniffing can be abused: an attacker uploads a file that looks like an image but contains script, and hopes the browser "sniffs" it as executable code. With nosniff, the browser respects the declared type and refuses to run it as something else.

The risk
Without nosniff, a browser may misinterpret an uploaded or user-supplied file as executable code, opening the door to script execution.

How Pentrawl checks it

Pentrawl checks your response headers for X-Content-Type-Options. If it's set (to nosniff), the check passes; if missing, it's flagged as an issue.

How to fix it

Add the header to your server configuration. There is only one meaningful value, and it should always be set.

Recommended
X-Content-Type-Options: nosniff
Check your domain's X-Content-Type-Options in seconds
Pentrawl scans this and 20+ other security checks in one automated pass.
Scan your website →