Skip to content
FlexibleToolsAI
Security Toolkit · Free, Nothing Stored

Security Headers Checker

Check how well a website uses the HTTP headers that protect visitors. Enter a URL to get a grade from A+ to F based on Content-Security-Policy, Strict-Transport-Security, X-Frame-Options, X-Content-Type-Options, Referrer-Policy and Permissions-Policy, with the exact header to add for each missing one.

Enter a URL and our server fetches it (following redirects) and grades the final response's headers. Each of the six protective headers is checked and explained; a weak CSP (such as 'unsafe-inline' scripts) is flagged, and information leaks like Server version numbers and X-Powered-By are noted. A+ needs all six plus a strong CSP.

Instant Results

Live checks in seconds

Nothing Stored

No logs of what you check

No Sign-Up

Free, no credits or email

Suggest a Feature or Improvement for Security Headers Checker

Need custom options, higher limits, or extra format support? Let our engineering team know!

How to use Security Headers Checker

  1. 1Enter the page URL.
  2. 2Review the grade and the findings.
  3. 3Add the missing headers using the fixes shown.
  4. 4Re-scan to confirm your grade improved.

The headers that matter

Content-Security-Policy limits where scripts can load from, the strongest defence against XSS. Strict-Transport-Security forces HTTPS on future visits. X-Frame-Options (or CSP frame-ancestors) stops clickjacking. X-Content-Type-Options: nosniff prevents content-type confusion. Referrer-Policy controls what URLs leak to other sites. Permissions-Policy disables browser features you don't use.

Deprecated headers like X-XSS-Protection and Expect-CT no longer help and can be removed.

Adding them

Set headers in your web server (Nginx add_header, Apache Header set), CDN (Cloudflare Transform Rules), or framework (Next.js headers(), Helmet for Express). Roll out CSP in Report-Only mode first with the CSP Header Generator, and analyse an existing policy with the CSP Evaluator.

Frequently Asked Questions

Does a good grade mean my site is secure?

No — headers are one layer. They make common attacks harder but don't fix vulnerabilities in your code, plugins or server.

Why does my grade differ from securityheaders.com?

Grading scales differ slightly. We grade the same core headers and additionally require a CSP without high-severity weaknesses for A+.

What do you do with the domains and URLs I check?

Our server performs the lookup once and returns the result to your browser. We don't store the addresses you check or build a history. Private and internal addresses are blocked.

Guides & Tutorials

Related Tools