Help shield your org and network from malicious attacks with content sniffing protection. This change helps prevent the browser from loading scripts disguised as other file types when your users access external content and websites from Salesforce. This update was first made available in Winter ’23 and was scheduled to be enforced in Spring ’23, but we postponed the enforcement date to Summer ’23.

Where: This change applies to Lightning Experience and Salesforce Classic in all editions.

When: Salesforce enforces this update in Summer ’23. To get the major release upgrade date for your instance, go to Trust Status, search for your instance, and click the maintenance tab.

Why: Content sniffing is the practice of using the content within a file to automatically determine the file’s Multipurpose Internet Mail Extensions (MIME) type. This process is also called media type sniffing or MIME sniffing, and it can help websites display content with missing or incomplete metadata.

In a cross-site scripting (XSS) attack, an attacker includes malicious code in a client-side script within a legitimate web page or web application. With content sniffing, these malicious files can be misidentified and delivered to the user’s browser.

When you enable content sniffing protection, the X-Content-Type-Options: nosniff HTTP header is added to all pages in Salesforce. This change prevents external content accessed from Salesforce from loading unless the server provides metadata for the resource.

How: To review this update, from Setup, in the Quick Find box, enter Release Updates, and then select Release Updates. For Enable Content Sniffing Protection, follow the testing and activation steps.

To test the effect of this release update, from Setup, in the Quick Find box, enter Session Settings, and then click Session Settings. Select Enable Content Sniffing protection and save your changes. Then test external links and embedded content. In particular, focus on external links that you added, such as hyperlinks and embedded content on custom Visualforce pages.

Enable Content Sniffing Protection (Release Update) (salesforce.com)

Privacy Preference Center