
Security headers tell browsers how to protect a site's visitors. See which ones a website sets, what's missing, and how to fix it.
Enter any public website. The check follows its redirects and grades the headers on the final page. Only the headers are read; the page itself is never downloaded.
Security headers are instructions a website sends with every page telling the browser how to protect visitors, for example which scripts may run (Content-Security-Policy), to always use HTTPS (Strict-Transport-Security) and not to let other sites frame the page (X-Frame-Options).
At minimum: Content-Security-Policy, Strict-Transport-Security, X-Content-Type-Options: nosniff, a framing rule (X-Frame-Options or CSP frame-ancestors), Referrer-Policy and Permissions-Policy. Cross-Origin-Opener-Policy is a useful extra.
Each header is worth points based on how much protection it gives: Content-Security-Policy 25, HSTS 20, framing protection 15, X-Content-Type-Options 15, Referrer-Policy 10, Permissions-Policy 10 and COOP 5. Weak settings score partial points, and the total is converted to a grade from A+ (95+) to F.
Yes. The checker makes one normal request, exactly like a browser visiting the page, and only reads the response headers. It doesn't scan, probe or download the page.