SEO-32

Missing X-Content-Type-Options: nosniff

WarningCrawler access

What the check measures

In the response headers of the home page we look for X-Content-Type-Options: nosniff. If it is missing, the finding is raised. As with SEO-31, only the home page is checked, only presence, and only on a fresh crawl. Without headers the check stays quiet rather than reporting a missing value.

What the check does not do: it checks no other pages and no other security headers, it does not judge whether files can be uploaded to the site at all (that is, whether this header matters in your case), and it cannot see a header added at the CDN layer if the audit reaches the origin directly.

The finding attaches to the home page; severity is warning.

How strong the evidence is

Effect not demonstrated

We recommend it because it does no harm or has some other benefit, but we promise nothing about whether it makes language models cite you. Nobody has demonstrated that yet.

For visibility in AI and for ranking we have no documented effect and claim none. It is a security header, not an SEO measure: it appears next to SEO findings in the report, but it is not meant to be read that way.

What it does is simple and documented: it forbids the browser from guessing a file's type from its contents when the declared type looks wrong. Without it, a file the server sends as plain text can be evaluated as a script, and executed.

When it genuinely matters: when people upload files to your site. User attachments, images in a discussion, downloadable documents. There, “type sniffing” is a route for slipping a script in under the guise of a harmless file. On a static site with no uploads it is a measure for completeness.

The practical conclusion: it is one line of server configuration with no risk attached (unlike HSTS), so add it. But do not expect it to move any number.

How to fix it

One header on all responses:

# nginx
add_header X-Content-Type-Options "nosniff" always;

# Apache
Header always set X-Content-Type-Options "nosniff"
  • The value has exactly one valid form: nosniff. Nothing else is set.
  • always in nginx is not cosmetic: without it the header is not added to error responses (404, 500), and those are often the route by which content is slipped in.
  • Add it globally, not per block. Missing on one file type means the measure does not apply there.
  • Check that your content types are declared correctly. nosniff means the browser trusts what you send, and if you serve CSS as text/plain, it will stop being applied once you switch it on.

Verification:

curl -sI https://your-domain/ | grep -i x-content-type-options

What the report says about it

Finding description

The homepage does not send an `X-Content-Type-Options: nosniff` header. Without it, the browser may guess a different content type than the server declared for some responses, which makes MIME-sniffing attacks easier. This is a standard security recommendation; we have no evidence it affects visibility in AI assistant answers.

Recommendation

Add the `X-Content-Type-Options: nosniff` header to all responses at the server/CDN level.

Sources

Text verified 2026-09-12