Security Headers Checker
Security headers tell browsers how strictly to treat a page. This check fetches the homepage and lists which protective headers are sent, with their raw values, so you can see what is missing and what to add.
Results open in the site's full report, which you can share, compare and re-run.
What it checks
- Strict-Transport-Security (HSTS)
- Content-Security-Policy, including frame-ancestors
- X-Frame-Options and X-Content-Type-Options
- Referrer-Policy and Permissions-Policy
Frequently asked questions
- Does a present header mean the site is secure?
- No. The report shows presence and the raw value. A CSP that allows everything is present but weak, so review the value itself.
- Which header matters most?
- HSTS and a Content-Security-Policy give the most protection: HSTS prevents HTTPS downgrades and CSP limits the damage of injected scripts.
- Where do I add these headers?
- In your web server, CDN or framework configuration, for example nginx add_header, Cloudflare Transform Rules or next.config headers().
More free tools
- SSL Certificate Checker
- SPF & DMARC Checker
- Technology & CMS Detector
- AI Crawler Access Checker
- llms.txt Checker
- llms.txt Generator
- robots.txt Tester
- XML Sitemap Checker
- Website Speed Test
- Website Carbon Calculator
- Canonical Tag Checker
- Hreflang Checker
- Redirect & Broken Link Checker
- Duplicate Title & Description Checker
- Structured Data Checker
- Core Web Vitals Checker