Skip to content
All tools

/security-headers

Security Headers

Check for HSTS, CSP, X-Frame-Options and other security headers.

Try:

About Security Headers

Security Headers checks a website's response for the specific headers browsers rely on to enforce protections like forced HTTPS, restricted script sources and clickjacking prevention, reporting which are present and which are missing.

Each header is scored individually with an explanation of what it actually protects against, rather than folded into a single pass or fail result, since a site can be missing one header while every other protection is correctly configured.

Run this after a server configuration change, as part of a routine security review, or whenever you want a plain answer to what specific protections a site's headers are and are not currently providing.