Security Header Checker

Security headers tell browsers how to protect a site's visitors. See which ones a website sets, what's missing, and how to fix it.

Check a website's security headers

Enter any public website. The check follows its redirects and grades the headers on the final page. Only the headers are read; the page itself is never downloaded.

Questions

What are HTTP security headers?

Security headers are instructions a website sends with every page telling the browser how to protect visitors, for example which scripts may run (Content-Security-Policy), to always use HTTPS (Strict-Transport-Security) and not to let other sites frame the page (X-Frame-Options).

Which security headers should every website have?

At minimum: Content-Security-Policy, Strict-Transport-Security, X-Content-Type-Options: nosniff, a framing rule (X-Frame-Options or CSP frame-ancestors), Referrer-Policy and Permissions-Policy. Cross-Origin-Opener-Policy is a useful extra.

How is the grade worked out?

Each header is worth points based on how much protection it gives: Content-Security-Policy 25, HSTS 20, framing protection 15, X-Content-Type-Options 15, Referrer-Policy 10, Permissions-Policy 10 and COOP 5. Weak settings score partial points, and the total is converted to a grade from A+ (95+) to F.

Is it safe to check a site I don't own?

Yes. The checker makes one normal request, exactly like a browser visiting the page, and only reads the response headers. It doesn't scan, probe or download the page.

Can I use cookie-free analytics to count page visits? No ads, no tracking across sites. Privacy policy ·