Google’s John Mueller discussed the importance of using security headers in client technical SEO audits. While he highlighted one specific header as beneficial for SEO, neglecting other security headers could lead to a negative impact on SEO.

What do security headers refer to?

Security headers are guidelines transmitted from web servers to browsers to inform them on securely handling content and safeguarding against various web-based attacks such as cross-site scripting, clickjacking, and malicious script injection.

Examples of the types of threats that security headers guard against:

  • Data theft involves the act of unlawfully acquiring confidential user data.
  • Session hijacking involves unauthorized access to a user’s active login session.
  • Intercepting the traffic between the browser and server is known as man-in-the-middle attacks.

Which Security Headers Should Be Included in an SEO Audit?

The Reddit user who asked the question was looking for recommendations on the security headers to include in a technical SEO audit.

They inquired:

Are there any other security headers I should consider besides CSP, X-Frame, X-Content, and Permissions Policy for conducting a full security header review audit on my website and for clients?

John Mueller from Google mentioned that the X-Frame-Options security header could be beneficial in a technical SEO evaluation and provided a brief rationale. While his response is a typical one, there is additional information regarding security headers and SEO beyond what Mueller discussed.

His reply:

The only security headers that may impact SEO are those that prevent iframing from other sites, such as the x-frame-options header or CSP frame-ancestors. Otherwise, security headers primarily focus on security.

John Mueller is accurate in stating that the X-Frame-Options security header is the security header most directly associated with SEO. However, he overlooks other security headers that have an indirect impact on SEO.

The Importance of X-Frame-Options Security Header for SEO

The X-Frame-Options header, in use for nearly two decades, remains important as it prevents other websites from displaying your site’s content within an iframe, thereby safeguarding against content theft and unauthorized ranking on search engines like Google.

What are Security Headers all about?

There are six fundamental security headers and five additional ones designed for specific scenarios. I believe they are beneficial for SEO since a hacked website may lose its keyword rankings. Therefore, integrating certain security headers into an SEO audit is recommended, similar to reviewing the WordPress plugins in use.

Security headers that are mandatory

HSTS enforces secure HTTPS connections when browsers connect to the website.

The nosniff Directive in the X-Content-Type-Options header helps to reduce the risk of cross-site scripting attacks, although it is not a complete solution.

This stops other websites from embedding your content in iframes and benefiting from it in search rankings.

Strongly suggested

Content-Security-Policy (CSP) limits the content sources that a browser can load to prevent XSS and data injection attacks.

Security headers that are not mandatory

This determines the extent of referrer information shared with other sites upon a user clicking an external link. It can also be specified using HTML, such as through the meta tag or link attribute.

This header limits the browser features and hardware APIs that a website can access and is not supported by many popular browsers. Additional details can be found on the Mozilla Developer Network website.

SEO and Security Headers – Are They Related?

It is crucial for SEO to implement security headers on a website to prevent it from losing its ranking, as recommended by John Mueller. The X-Frame-Options header is emphasized, but other core security headers are also essential for an SEO audit.

While the majority of security headers do not have a direct impact on SEO, they provide protection that aids in preserving search visibility. Additionally, security headers can uphold user trust and experience by safeguarding against malicious scripts, securing sensitive information, and enforcing privacy measures.

Private content management systems such as Wix automatically establish security headers, while websites using WordPress can configure these headers using plugins.

For instance, these WordPress plugins can all include security headers.

  • AIOSEO stands for All in One SEO
  • W3 Total Cache is abbreviated as W3TC.
  • Very Basic Security
  • the widely used Redirection plugin

Neither Sucuri Security nor Wordfence provide security header features. AIOSEO acknowledges the importance of security headers, which raises questions about why popular SEO plugins like Yoast SEO and Rank Math do not offer this functionality.

In my view, including security headers in an SEO audit and conducting a basic security assessment of a website is essential. Verifying security headers can be done easily using tools like SecurityHeaders.com or similar free services available online.

Image provided by Shutterstock/Titima Ongkantong

LEAVE A REPLY

Please enter your comment!
Please enter your name here