Security Headers Checker

Check your domain's HTTP security headers and get an instant grade. We analyse HSTS, CSP, X-Frame-Options, and more with clear recommendations to fix any issues.

Enter a domain name. Full URLs are accepted — the hostname will be extracted automatically.

Want ongoing security header monitoring?
Sign up free to track changes and get alerted when security headers are removed or weakened.
What we check

Strict-Transport-Security

Forces browsers to use HTTPS, preventing downgrade attacks and cookie hijacking.

Content-Security-Policy

Controls which resources the browser can load, significantly reducing XSS attack surface.

X-Frame-Options

Prevents your page from being embedded in iframes, blocking clickjacking attacks.

X-Content-Type-Options

Stops browsers from guessing content types, preventing MIME-sniffing attacks.

Referrer-Policy

Controls how much URL information is shared when users navigate away from your site.

Permissions-Policy

Restricts access to sensitive browser APIs like camera, microphone, and geolocation.