# Sec-Fetch-Dest Header: All Values Explained

> Sec-Fetch-Dest tells the server where a response will be used: document, iframe, image, script, empty. Full value list and server-side uses.

Source: https://howhttpworks.com/headers/sec-fetch-dest
Last reviewed: 2026-10-04

> **TL;DR:** `Sec-Fetch-Dest` tells your server what the browser will do with the response: render it as a `document`, put it in an `iframe`, use it as an `image`, run it as a `script`, or hand it to JavaScript (`empty`). It lets you refuse, for example, to serve a JSON endpoint to an `<img>` tag or a private page to an `<iframe>` on another site.

## Example

```http
GET /avatar.png HTTP/1.1
Host: example.com
Sec-Fetch-Dest: image
Sec-Fetch-Mode: no-cors
Sec-Fetch-Site: cross-site
```

This is a cross-site `<img>`: another site is hotlinking your image. The header is a structured-field token (section 2.1 of the W3C Fetch Metadata spec) and a forbidden request header, so scripts cannot set it.

## Values

From MDN's current list, with what produces each:

| Value | Source |
| --- | --- |
| `audio` | `<audio>` |
| `audioworklet` | `audioWorklet.addModule()` |
| `document` | A top-level navigation |
| `embed` | `<embed>` |
| `empty` | `fetch()`, `XMLHttpRequest`, `navigator.sendBeacon()`, `EventSource`, `WebSocket` and other requests with no specific destination |
| `fencedframe` | The Fenced Frame API (Chromium only) |
| `font` | CSS `@font-face` |
| `frame` | `<frame>` |
| `iframe` | `<iframe>` |
| `image` | `<img>`, SVG `<image>`, CSS `background-image` and similar |
| `json` | `import ... with { type: "json" }` |
| `manifest` | `<link rel="manifest">` |
| `object` | `<object>` |
| `paintworklet` | `CSS.paintWorklet.addModule()` |
| `report` | CSP and other violation reports |
| `script` | `<script>`, `importScripts()` |
| `serviceworker` | `navigator.serviceWorker.register()` |
| `sharedworker` | `new SharedWorker()` |
| `style` | `<link rel="stylesheet">`, CSS `@import`, `import ... with { type: "css" }` |
| `text` | `import ... with { type: "text" }` |
| `track` | `<track>` |
| `video` | `<video>` |
| `webidentity` | FedCM identity endpoints |
| `worker` | `new Worker()` |
| `xslt` | XSLT transforms |

The list follows the Fetch Standard's request destinations and grows with the platform, so write server rules as an allow-list for the destinations you expect rather than a deny-list of known-bad ones.

## Practical uses

- **Refuse to be framed or embedded.** A cross-site request with `Sec-Fetch-Dest: iframe`, `frame`, `embed` or `object` to a page that has no business being framed can get a `403`. `frame-ancestors` in [Content-Security-Policy](https://howhttpworks.com/headers/content-security-policy) is the browser-enforced way to do it, and it covers browsers that do not send this header.
- **Stop JSON endpoints being loaded as scripts.** An API that only serves `empty` destinations should reject `script`, which is the shape of old JSONP-style cross-site data theft.
- **Cut hotlinking.** Reject `image`, `video` or `audio` destinations when `Sec-Fetch-Site` is `cross-site` and send an alternative.
- **Separate navigations from XHR.** `document` is a person opening a page, `empty` is code calling an API. Same URL, different handling, with `Vary: Sec-Fetch-Dest` if anything is cached.

```nginx
# Serve downloads only to navigations and same-site code, never to cross-site embeds
map "$http_sec_fetch_site:$http_sec_fetch_dest" $block_embed {
    default                          0;
    "~^cross-site:(iframe|frame|embed|object)$"  1;
}
```

Then `if ($block_embed) { return 403; }` in the relevant `location`. The full policy that combines Dest with Site and Mode is on the [Sec-Fetch-Site](https://howhttpworks.com/headers/sec-fetch-site) page.

## Browser support

Chrome and Edge 80, Firefox 90, Safari 16.4. Sent only to potentially trustworthy URLs (HTTPS and `localhost`). Absent for curl and server-side clients.

## Related

- [Sec-Fetch-Site](https://howhttpworks.com/headers/sec-fetch-site), [Sec-Fetch-Mode](https://howhttpworks.com/headers/sec-fetch-mode), [Sec-Fetch-User](https://howhttpworks.com/headers/sec-fetch-user)
- [Content-Security-Policy](https://howhttpworks.com/headers/content-security-policy) and [X-Frame-Options](https://howhttpworks.com/headers/x-frame-options)
