Skip to content
  • GDPR-compliant
  • 100% hosting in Germany
  • Personal contact
  • Support included
  • Provisioning within 24 hours
ShieldCache 3 min read

Content Security Policy and custom headers with ShieldCache

The Content Security Policy (CSP) specifies from which sources the browser may load scripts, styles, images and other content for your site. This makes life much harder for injected scripts (XSS). ShieldCache sets the CSP for you - you will find it under Settings > Headers.

The three modes

  • Off: no CSP from ShieldCache. A CSP from your server or the header template remains as before.
  • Report only: The browser does not block anything, but reports every violation (Report-Only). Ideal for testing.
  • Enforce: The browser blocks everything the policy does not allow and reports it.

Step by step: report first, then enforce

  1. Choose the Report only mode.
  2. Create directives. Start, for example, with default-src and the source 'self' (your own domain), plus img-src with 'self' and data: or script-src with https://cdn.muster.de. Below each directive, the allowed keywords and schemes are listed for quick adding; invalid entries are explained as you type.
  3. Click Save and then Apply.
  4. Check the reported violations for a few days. With Take over from reports, the customer area suggests the reported sources for the matching directive - only take over what your site really needs.
  5. Only when no more legitimate reports come in, switch to Enforce.
Content Security Policy card with the modes Off, Report only and Enforce
The CSP card with mode, directives and a preview of the header.

unsafe-inline and unsafe-eval

'unsafe-inline' and 'unsafe-eval' allow inline code and eval() respectively and remove a large part of the protection. Hashes ('sha256-...') or external files are better. Nonces and http:// sources are not possible.

Good to know

  • With “Report only” or “Enforce”, ShieldCache replaces a CSP from your server. The ShieldCache error and check pages keep their own strict policy.
  • Upgrade insecure requests to HTTPS (upgrade-insecure-requests) follows the header template by default. When reporting, ShieldCache also sends this directive as an enforced policy, because Report-Only does not support it.
  • The preview shows the header exactly as visitors receive it - at most 4096 characters. If it becomes too long, combine sources, for example with *.muster.de.
  • The browser reports violations to /.shieldcache/csp-bericht on your own domain.

Reported violations

The Reported violations card groups identical reports: directive, blocked source, page (without parameters), mode, count and last report. New reports appear after about 10 seconds, instantly with ↻. “Only since the last apply” hides older reports. No IP addresses are stored; entries expire 30 days after the last report.

Reported Content Security Policy violations
Reported violations: filter by mode, period since the last apply and search.

Custom headers

  • Set headers: name and value, for example X-Frame-Options = DENY or a Permissions-Policy. Up to 20 headers.
  • Remove headers: headers that your server sends and that should not go out, for example X-Powered-By. Up to 20.

How they work together: The header template replaces headers of the same name from your server. Custom headers are set last and win over the template and server; “Remove headers” also removes headers from the template. ShieldCache error pages do not receive them.

Blocked are headers that ShieldCache manages itself (such as Content-Security-Policy, Strict-Transport-Security, Alt-Svc), that concern the structure of the response (such as Content-Length) or that are security-critical (such as Set-Cookie, Location). The complete list can be expanded below the card.

Setting and removing custom headers
Setting and removing custom headers, with the explanation of the order below.

Was this article helpful?

New to SpeedIT Solutions?

Hosting where you know someone.

What you are reading here is what we put into practice for our customers every day. Based in Isernhagen since 2009 - with dedicated contact persons rather than a call centre.

  • 100% hosted in Germany
  • GDPR-compliant
  • Dedicated contact person
  • Provisioning within 24 hours
4.9 88 reviews on Expeero

Sehr guter Hosting Service

Ich bin schon seit vielen Jahren Kunde und kann den vorbildlichen Service nur loben. Offene Fragen wurden kurzfristig beantwortet und Hilfestellung bei Konfiguration und Absicherung waren perfekt. Klare Empfehlung für mich.
Andreas W.Recommends us · 08/11/2026

100 % recommend us · Expeero

All reviews on HOSTtest (opens in a new window)

You might also be interested in:

Personal support

Of course, our support team is also happy to assist you personally. If you cannot find what you are looking for in our knowledge base or require personalised support, please do not hesitate to contact us. We’re here to help you and to ensure that your experience with our products and services is as smooth and enjoyable as possible.