Security glossary

Plain-English definitions of the web-security terms that decide whether your site is safe: unsafe-inline, script-src, SPF, DKIM, DMARC, CAA, CSP, XSS, clickjacking, HSTS and more. Every term here also appears as a hover explainer throughout the field manual.

'unsafe-eval'CSP keyword
A CSP value permitting eval() and other string-to-code execution. It lets an attacker turn plain data into running code, keep it out of script-src.
'unsafe-inline'CSP keyword
A Content-Security-Policy value that lets the browser run inline scripts or styles written directly in the page. In script-src it's the danger switch, it re-enables exactly the inline execution that injected XSS needs. Replace it with per-script hashes or a nonce.
~allSPF qualifier
The SPF 'soft fail' qualifier: mail from servers not on your list is marked suspicious rather than hard-rejected, the recommended starting posture.
a= tagBIMI tag
The part of a BIMI record holding the web address of your certificate file. Leave it out and Gmail will not display your logo, because nothing proves the logo belongs to you.
base-uriCSP directive
Restricts the page's <base> tag so an attacker can't silently rewrite every relative URL on the page.
baseProfile="tiny-ps"BIMI asset
A line inside the logo file declaring that it follows the strict BIMI image rules. Email apps and certificate issuers look for it, and a file without it is treated as the wrong format even when it looks identical.
BIMIEmail auth
Brand Indicators for Message Identification: a DNS record that tells email apps to show your logo beside your messages in the inbox. It only takes effect once DMARC is set to quarantine or reject, so the logo doubles as visible proof your email security is switched on.
blue checkmarkEmail auth
The small verified badge Gmail puts beside senders whose logo is backed by a trademark certificate. Only that certificate earns it, the cheaper and free routes show the logo with no badge.
CAATLS / PKI
Certification Authority Authorization: a DNS record naming which certificate authorities may issue TLS certificates for your domain, blocking rogue or mistaken issuance.
clickjackingAttack
An attack that invisibly frames your real site over a decoy, so victims click genuine buttons without knowing. Blocked by frame-ancestors or X-Frame-Options.
CMCTLS / PKI
Common Mark Certificate: the cheaper certificate for businesses with no registered trademark, granted once the issuer confirms you have used the same logo publicly for at least twelve months. Apple Mail accepts it, Gmail still asks for the full trademark version.
connect-srcCSP directive
Controls fetch(), XHR and WebSocket destinations, it limits where injected script could phone home or exfiltrate data.
CSPHTTP header
Content-Security-Policy: a response header that whitelists exactly which scripts, styles, images and connections a page may use, so an injected payload simply has no permission to run.
default-srcCSP directive
The CSP fallback directive, any resource type without its own rule (script, style, image, font…) inherits this one.
default._bimiEmail auth
The exact DNS name a BIMI record has to live at, written as default._bimi.yourdomain.com. Publish the same text anywhere else and email apps will never find it.
DKIMEmail auth
DomainKeys Identified Mail: a cryptographic signature added to your outgoing email and verified against a public key in your DNS. Unlike SPF, it survives forwarding.
DMARCEmail auth
Domain-based Message Authentication: a DNS policy telling receivers what to do with mail that fails SPF or DKIM, and which emails you a report of everyone spoofing you.
DNSInfrastructure
The Domain Name System, the internet's address book. It's also where you publish the SPF, DKIM, DMARC and CAA records that secure your domain.
form-actionCSP directive
Limits where forms are allowed to submit, so a hijacked form cannot POST credentials to an attacker-controlled server.
frame-ancestorsCSP directive
The CSP directive deciding who may embed your page in an <iframe>. Set to 'none' to make clickjacking impossible.
HSTSHTTP header
HTTP Strict Transport Security: a header that forces browsers to always use HTTPS for your domain, defeating downgrade and SSL-strip attacks.
l= tagBIMI tag
The part of a BIMI record holding the web address of your logo file. It must load over HTTPS straight from that address, because a redirect on the way there is enough to stop some email apps showing the logo.
markBIMI asset
The logo itself, the small square image an email app shows next to your name in the inbox. It has to be a simple square version of your logo on a solid background, not the wide one with your company name beside it.
MVATLS / PKI
Mark Verifying Authority: one of the very small number of companies allowed to issue BIMI certificates. They are the ones who check your trademark paperwork or your history of using the logo.
nonceCSP technique
A one-time random token placed in your CSP and on each allowed inline script per page load, it proves the script is yours without opening up all inline scripts.
p=noneDMARC policy
DMARC monitor mode: observe and report only, failing mail is still delivered. The safe place to start while you confirm your real mail passes.
p=quarantineDMARC policy
DMARC policy that sends failing (likely spoofed) mail to the spam folder instead of the inbox.
p=rejectDMARC policy
The strictest DMARC policy, mail that fails authentication is refused outright. The gold standard, once you have confirmed legitimate mail passes.
pct=DMARC policy
A DMARC setting that applies your policy to only a share of your mail while you test, for example nine messages in ten. Anything below 100 quietly disqualifies you from BIMI even though every DMARC checker still calls the record valid.
PEMTLS / PKI
The plain text file a certificate is delivered in. For BIMI it is the file your a= tag points to, and it has to contain the full chain back to the issuer or email apps will not trust it.
registered trademarkMark verification
A logo or name formally registered with a government trademark office. It is what the more expensive BIMI certificate is built on, and the office has to be one the certificate issuers recognise, such as those in the US, EU, UK, Canada, Australia or Japan.
script-srcCSP directive
The CSP directive that controls which scripts a page may load and execute. It is the single most important directive for stopping cross-site scripting (XSS).
security.txtDisclosure
An RFC 9116 standard file at /.well-known/security.txt that publishes how a researcher should report a vulnerability to you.
sha256 hashCSP technique
A fingerprint of an inline script's exact contents. Listing the hash in script-src authorizes that one specific script without needing 'unsafe-inline'.
sp=DMARC policy
The DMARC setting that covers your subdomains, such as mail.yourdomain.com. Leaving it looser than your main policy lets people spoof a subdomain and blocks BIMI outright, even when the main domain is at the strictest setting.
SPFEmail auth
Sender Policy Framework: a DNS record listing which mail servers are allowed to send email as your domain, so spoofed senders get flagged.
style-srcCSP directive
The CSP directive for stylesheets and inline styles. 'unsafe-inline' here is low-risk because inline style attributes can't be hashed, and CSS injection is far less dangerous than script injection.
SVG Tiny P/SBIMI asset
The only image format a BIMI logo may use, a stripped down version of SVG with no animation, no scripts and no links to anything outside the file. Ordinary logo exports, including PNG, JPG and normal SVG, are rejected.
v=BIMI1Email auth
The opening line of every BIMI record, marking it as version 1 of the standard. If it is missing or misspelled the whole record is ignored and no logo ever appears.
VMCTLS / PKI
Verified Mark Certificate: a paid certificate confirming that the logo in your BIMI record is your registered trademark. Gmail requires one before it will show your logo, and it is the only route to the verified badge.
Wayback MachineMark verification
A free public archive that keeps dated copies of websites. Certificate issuers use it to confirm you were already showing the same logo a year ago, which is how a business with no registered trademark can still qualify, and it also means the eligibility date can be worked out in advance.
X-XSS-ProtectionLegacy header
A deprecated header for a long-removed browser XSS filter that could itself introduce bugs. The correct modern value is 0 (off); rely on CSP instead.
XSSAttack
Cross-Site Scripting: an attack that injects attacker-controlled JavaScript into your page to steal sessions, keylog, or act as the user. A strong CSP is the primary defense.