Guide
Security headers
Safest defaults for HSTS and CSP, CMS presets for common platforms, and Report-Only testing before you tighten.
Where to find it
In My NovaMX open Website, then Site settings, then Security headers. You see your current status, can restore the safest defaults in one click, and can change only what your site needs without editing server config by hand.
Safest vs CMS presets
Safest uses a strict Content-Security-Policy without unsafe-inline. That is ideal for static sites and carefully built apps. WordPress, Drupal, Joomla, TYPO3, Magento and Shopware often inject critical CSS and scripts inline, so they need the matching CMS preset. Existing https origins from your live CSP are filled into the form. HSTS preload stays a support decision, not a self-service toggle.
Report-Only workflow
Choose Report-Only or Both to collect browser violation reports while visitors keep a working page. My NovaMX shows recent reports with the directive, blocked URL and document URL. The last 100 reports for 7 days are included; longer archive retention is planned as an optional add-on. When the list looks clean, switch to Enforce on the stricter preset.