Security Headers Checker
Check your domain's HTTP security headers and get an instant grade. We analyse HSTS, CSP, X-Frame-Options, and more with clear recommendations to fix any issues.
What we check
Strict-Transport-Security
Forces browsers to use HTTPS, preventing downgrade attacks and cookie hijacking.
Content-Security-Policy
Controls which resources the browser can load, significantly reducing XSS attack surface.
X-Frame-Options
Prevents your page from being embedded in iframes, blocking clickjacking attacks.
X-Content-Type-Options
Stops browsers from guessing content types, preventing MIME-sniffing attacks.
Referrer-Policy
Controls how much URL information is shared when users navigate away from your site.
Permissions-Policy
Restricts access to sensitive browser APIs like camera, microphone, and geolocation.