X-Content-Type-Options

Prevents MIME type sniffing by forcing browsers to respect the declared Content-Type header. This is a critical defense against content-based attacks.

Open the full interactive page