Technical
MIME sniffing
Also called X-Content-Type-Options.
MIME sniffing is the browser guessing a file's type from its bytes when the declared `Content-Type` looks wrong or is missing. It is how an upload served as plain text can end up running as HTML or script.
How it is measured
Read the response headers. A `Content-Type: text/plain` with no `X-Content-Type-Options: nosniff` leaves room to guess. With `nosniff`, the browser must follow the declared type and blocks a script or stylesheet served with the wrong one, printing a MIME type mismatch in the console.
Test by uploading a file with HTML inside and a `.txt` name, then fetch it and see whether it renders. `curl -I` on upload URLs shows the type the server really sends.
Worked example
A forum lets members attach files under `/files/`. An attacker uploads `notes.txt` containing a script tag. The server sends no Content-Type and no `nosniff`, so an older browser sniffs HTML and runs it on the forum's origin, with the member's cookies.
Adding `X-Content-Type-Options: nosniff`, a correct `text/plain`, and a separate domain for uploads stops it. A stylesheet that a misconfigured CDN labels `text/html` is now blocked as well, which is how the team finds the CDN fault.
How it differs
MIME sniffing is browser guessing, and `nosniff` turns it off. CSP limits which sources may run scripts on a page at all. `nosniff` fixes type confusion for a file, and CSP limits the page. Neither replaces the other.
Common errors
Sending no Content-Type. Sending `application/octet-stream` and expecting only a download. Setting `nosniff` while serving JavaScript as `text/plain`, which breaks the site. Serving user uploads from the main domain. Assuming modern browsers never sniff.
In practice
Add `X-Content-Type-Options: nosniff` to every response at the server or CDN, browse your site for blocked resources, and fix any wrong types it exposes. Serve user uploads from a different origin.