Security Headers Checker
Check how well a website uses the HTTP headers that protect visitors. Enter a URL to get a grade from A+ to F based on Content-Security-Policy, Strict-Transport-Security, X-Frame-Options, X-Content-Type-Options, Referrer-Policy and Permissions-Policy, with the exact header to add for each missing one.
Enter a URL and our server fetches it (following redirects) and grades the final response's headers. Each of the six protective headers is checked and explained; a weak CSP (such as 'unsafe-inline' scripts) is flagged, and information leaks like Server version numbers and X-Powered-By are noted. A+ needs all six plus a strong CSP.
Instant Results
Live checks in seconds
Nothing Stored
No logs of what you check
No Sign-Up
Free, no credits or email
Suggest a Feature or Improvement for Security Headers Checker
Need custom options, higher limits, or extra format support? Let our engineering team know!
How to use Security Headers Checker
- 1Enter the page URL.
- 2Review the grade and the findings.
- 3Add the missing headers using the fixes shown.
- 4Re-scan to confirm your grade improved.
The headers that matter
Content-Security-Policy limits where scripts can load from, the strongest defence against XSS. Strict-Transport-Security forces HTTPS on future visits. X-Frame-Options (or CSP frame-ancestors) stops clickjacking. X-Content-Type-Options: nosniff prevents content-type confusion. Referrer-Policy controls what URLs leak to other sites. Permissions-Policy disables browser features you don't use.
Deprecated headers like X-XSS-Protection and Expect-CT no longer help and can be removed.
Adding them
Set headers in your web server (Nginx add_header, Apache Header set), CDN (Cloudflare Transform Rules), or framework (Next.js headers(), Helmet for Express). Roll out CSP in Report-Only mode first with the CSP Header Generator, and analyse an existing policy with the CSP Evaluator.
Frequently Asked Questions
Does a good grade mean my site is secure?
No — headers are one layer. They make common attacks harder but don't fix vulnerabilities in your code, plugins or server.
Why does my grade differ from securityheaders.com?
Grading scales differ slightly. We grade the same core headers and additionally require a CSP without high-severity weaknesses for A+.
What do you do with the domains and URLs I check?
Our server performs the lookup once and returns the result to your browser. We don't store the addresses you check or build a history. Private and internal addresses are blocked.
Guides & Tutorials
Related Tools
CSP Evaluator
Analyse a Content-Security-Policy for bypasses and weaknesses — paste it or fetch it from a URL.
SSL Checker
Check a site's SSL/TLS certificate, chain, expiry, TLS versions, HTTPS redirect and HSTS.
HTTP Header Checker
View every HTTP response header a URL returns, with explanations and the redirect chain.