X-Content-Type-Options
X-Content-Type-Options
 The X-Content-Type-Options response HTTP header is a marker used by the server to indicate that the MIME types advertised in the Content-Type headers should be followed and not be changed. The header allows you to avoid MIME type sniffing by saying that the MIME types are deliberately configured. 
This header was introduced by Microsoft in IE 8 as a way for webmasters to block content sniffing that was happening and could transform non-executable MIME types into executable MIME types. Since then, other browsers have introduced it, even if their MIME sniffing algorithms were less aggressive.
 Starting with Firefox 72, top-level documents also avoid MIME sniffing (if Content-type is provided). This can cause HTML web pages to be downloaded instead of being rendered when they are served with a MIME type other than text/html. Make sure to set both headers correctly. 
Site security testers usually expect this header to be set.
 Note: X-Content-Type-Options only apply request-blocking due to nosniff for request destinations of "script" and "style". However, it also enables Cross-Origin Read Blocking (CORB) protection for HTML, TXT, JSON and XML files (excluding SVG image/svg+xml). 
| Header type | Response header | 
|---|---|
| Forbidden header name | no | 
Syntax
X-Content-Type-Options: nosniff
Directives
- nosniff
-  Blocks a request if the request destination is of type styleand the MIME type is nottext/css, or of typescriptand the MIME type is not a JavaScript MIME type.
Specifications
| Specification | 
|---|
| Fetch Standard (Fetch) # x-content-type-options-header | 
Browser compatibility
| Desktop | Mobile | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Chrome | Edge | Firefox | Internet Explorer | Opera | Safari | WebView Android | Chrome Android | Firefox for Android | Opera Android | Safari on IOS | Samsung Internet | |
| X-Content-Type-Options | 64 1 Not supported for stylesheets. | 12 | 50 | 8 | Yes | 11 | 64 Yes Not supported for stylesheets. | 64 Yes Not supported for stylesheets. | 50 | Yes | 11 | 9.0 Yes Not supported for stylesheets. | 
Browser specific notes
-  Firefox 72 enables X-Content-Type-Options: nosnifffor top-level documents
See also
- Content-Type
- The original definition of X-Content-Type-Options by Microsoft.
- The Mozilla Observatory tool testing the configuration (including this header) of Web sites for safety and security
- Mitigating MIME Confusion Attacks in Firefox
- Cross-Origin Read Blocking (CORB)
- Google Docs CORB explainer
    © 2005–2021 MDN contributors.
Licensed under the Creative Commons Attribution-ShareAlike License v2.5 or later.
    https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/X-Content-Type-Options