🗂️ .htaccess Security Snippet Generator

Check the protections you want and copy the generated Apache .htaccess snippet.

What the checkboxes write

Each box adds one commented block to a snippet you copy into a .htaccess file - nothing is checked against your server. The "basic security headers" box emits three, not the two in its label:

<IfModule mod_headers.c>
    Header set X-Content-Type-Options "nosniff"
    Header set X-Frame-Options "SAMEORIGIN"
    Header set Referrer-Policy "strict-origin-when-cross-origin"
</IfModule>

The rules use Apache 2.4 access syntax - Require all denied. On an Apache 2.2 host that line is a fatal error and the whole site returns 500; there you need Order allow,deny with Deny from all instead.

Before you paste it

Nginx, Caddy and IIS have no equivalent of this file. If your host is not Apache or LiteSpeed, the snippet is inert.

Frequently asked questions

Why is my .htaccess file being ignored?

Usually AllowOverride None in the server config, which has been the default since Apache 2.3.9. Check the error log too - a directive from a module that is not loaded gives a 500 rather than silence, unless it is wrapped in IfModule as the header block above is.

Does blocking dotfiles protect an exposed .git folder?

Not on its own, because the files inside it have ordinary names. Test it: ask for /.git/config and see whether you get the contents back. The real fix is not deploying the directory at all.

Why does the HTTPS redirect loop?

Behind a load balancer or CDN the connection to Apache is plain HTTP, so %{HTTPS} is always off and the rule redirects forever. Test the forwarded header instead: RewriteCond %{HTTP:X-Forwarded-Proto} !https.