X-Content-Type-Options Header Missing
Microsoft IIS webserver
- Start the application named: IIS Manager.
- Select your website
- On the right part of the screen, access the option named: HTTP Response Headers.
- On the top right part of the screen, click on the Add option.
-
To enable the X-Content-Type-Options header, enter the following configuration:
• NAME: X-Content-Type-Options
• VALUE: nosniff
Nginx webserver
In your nginx.conf file add:
add-header X-Content-Type-Options "nosniff";
Apache webserver
Make sure that the headers module is loaded: sudo a2enmod headers
Add the following code to the apache2.conf file:
<IfModule mod_headers.c>
Header always set X-Content-Type-Options "nosniff"
</IfModule>