Test your HTTP security headers
Security headers are instructions your server sends to the browser that switch on built-in protections against cross-site scripting, clickjacking, downgrade attacks and data leaks. Enter your site to see which of them are set, which are weak, and which are missing.
What this is, and isn't. A passive check: we request the address you enter the way a browser would and inspect the response. It doesn't test for SQL injection, XSS, weak passwords or software bugs, so a good grade is not a guarantee of security. Only scan sites you own or are authorised to test. Scans are rate limited and results are not stored.
Security Headers Checker: 3 simple steps
- 1
Enter your domain name.
- 2
Review each header: Content-Security-Policy, HSTS, X-Frame-Options, X-Content-Type-Options, Referrer-Policy and Permissions-Policy.
- 3
Copy the suggested configuration for your server and re-scan to confirm.
For each header you get an explanation and ready-to-paste configuration for Nginx, Apache, Netlify and Node/Express. The scan also checks HTTPS redirects, cookie flags and mixed content because they are closely related.
Built for speed and privacy
- Tests all the headers browsers rely on
- Flags weak values, not just missing headers
- Copy-paste config for four server setups
- Free, no signup, results not stored
Security Headers Checker FAQ
At minimum: Strict-Transport-Security, X-Content-Type-Options: nosniff, a clickjacking control (X-Frame-Options or CSP frame-ancestors) and a Referrer-Policy. A Content-Security-Policy gives the most protection but needs testing.
It can, if the policy blocks scripts or styles your pages use. Start with a report-only policy, review the violations, then enforce it. Sites with inline scripts need nonces or hashes.
Add a [[headers]] block to netlify.toml or a _headers file. Note that headers on pages rendered by edge or serverless functions must be set in the function response as well. The fix snippets above show both styles.
No. Headers add browser-side protection but do not fix vulnerable code, weak passwords or outdated software. Treat them as one layer of defence.
More free tools
Need help hardening your stack?
We configure headers, TLS, firewalls and deployments as part of our cloud and maintenance services.