The `X-Content-Type-Options: nosniff` header allows a server to assert that its resources may only be executed as script or applied as style if they're delivered with appropriate `Content-Type` headers.


Established standard

Status in Chromium


Enabled by default (tracking bug) in:

  • Chrome for desktop release 64
  • Chrome for Android release 64
  • Android WebView release 64

Consensus & Standardization

After a feature ships in Chrome, the values listed here are not guaranteed to be up to date.


Last updated on 2020-11-09