Free · No signup · Passive check

Test your HTTP security headers

Security headers are instructions your server sends to the browser that switch on built-in protections against cross-site scripting, clickjacking, downgrade attacks and data leaks. Enter your site to see which of them are set, which are weak, and which are missing.

What this is, and isn't. A passive check: we request the address you enter the way a browser would and inspect the response. It doesn't test for SQL injection, XSS, weak passwords or software bugs, so a good grade is not a guarantee of security. Only scan sites you own or are authorised to test. Scans are rate limited and results are not stored.

How it works

Security Headers Checker: 3 simple steps

  1. 1

    Enter your domain name.

  2. 2

    Review each header: Content-Security-Policy, HSTS, X-Frame-Options, X-Content-Type-Options, Referrer-Policy and Permissions-Policy.

  3. 3

    Copy the suggested configuration for your server and re-scan to confirm.

For each header you get an explanation and ready-to-paste configuration for Nginx, Apache, Netlify and Node/Express. The scan also checks HTTPS redirects, cookie flags and mixed content because they are closely related.

Why use it

Built for speed and privacy

  • Tests all the headers browsers rely on
  • Flags weak values, not just missing headers
  • Copy-paste config for four server setups
  • Free, no signup, results not stored
FAQ

Security Headers Checker FAQ

At minimum: Strict-Transport-Security, X-Content-Type-Options: nosniff, a clickjacking control (X-Frame-Options or CSP frame-ancestors) and a Referrer-Policy. A Content-Security-Policy gives the most protection but needs testing.

It can, if the policy blocks scripts or styles your pages use. Start with a report-only policy, review the violations, then enforce it. Sites with inline scripts need nonces or hashes.

Add a [[headers]] block to netlify.toml or a _headers file. Note that headers on pages rendered by edge or serverless functions must be set in the function response as well. The fix snippets above show both styles.

No. Headers add browser-side protection but do not fix vulnerable code, weak passwords or outdated software. Treat them as one layer of defence.

Need help hardening your stack?

We configure headers, TLS, firewalls and deployments as part of our cloud and maintenance services.