Free · no account required

Security headers checker

Check the HTTP security headers of a public website online. Enter a domain to see how eight key security headers are rated on the final response and, where shown, the value observed.

Only public, low-impact signals. No ports, exploits, credentials or private targets.

No signup No destructive traffic Private ranges blocked
Header reference

What each header does and how it is rated

The checker reads these headers on one response. Most rows are presence checks: a header that is sent counts, and its value is shown where available so you can judge whether it suits your site.

HeaderWhat it doesWhat good looks likeHow this checker rates it
Strict-Transport-SecurityMakes returning browsers switch to HTTPS on their own, before any request leaves in plain HTTP.A long max-age (180 days or more) once your ramp-up is done; the guide covers the stages.Missing on an HTTPS target: medium. Not rated when you enter an http:// address.
Content-Security-PolicyGives the browser an allowlist of sources for the page's code and content.A policy built from the resources your pages really use, without broad script exceptions.Missing: medium. The value is shown but not reviewed.
X-Frame-Options · frame-ancestorsStops other sites from showing your page inside a frame of theirs.frame-ancestors in your CSP, with X-Frame-Options as a fallback for older browsers.Neither present: medium.
X-Content-Type-OptionsMakes the browser trust the declared content type of each response.The single value nosniff.Missing or any other value: low.
Referrer-PolicyLimits which part of your page address other sites see when visitors follow your links.A policy at least as strict as the current browser default.Missing: low.
Access-Control-Allow-OriginDecides which other sites' scripts may read your responses.Not sent on ordinary pages, or naming one trusted origin.A wildcard (*): medium.
Server · X-Powered-ByAnnounces the software behind the response.Removed, or reduced to a generic value.Any Server or X-Powered-By header: low, even without a version number. Only recognised technology names are shown.
Set-CookieSets cookies; its attributes decide which scripts can read them and when they are sent.Session cookies hidden from scripts and sent over HTTPS only.A cookie on this response without HttpOnly, or without Secure on HTTPS: medium. SameSite is not checked, and cookie values are never shown.

Permissions-Policy and Cross-Origin-Opener-Policy are not rated on this page. The launch readiness snapshot counts them only in its separate hardening grade.

Reading the result

How to read each status.

  1. 01PassedThe header was found and meets the presence check.
  2. 02Low · Medium · HighSomething is missing or set in a way this check flags. The level is the same one the full snapshot uses.
  3. 03ObservedA value was recorded, but the check produced neither a pass nor a finding.
  4. 04Nothing observedThe check ran but there was nothing to record, for example no cookie on the response.
  5. 05Not applicableThe check does not apply, for example HSTS when you enter an http:// address.
  6. 06Not measuredNo usable response was received, so the check is not counted as passed.
Scope

What this checker does not do.

  1. 01It requests only the home page of the origin you enter. Paths and query strings are dropped, and no other page is requested.
  2. 02It mostly checks whether a header is present, not whether its value suits your site.
  3. 03It tests the HTTP to HTTPS redirect only when you enter the http:// address; that run skips TLS and does not report a missing HSTS header.
  4. 04It is not a vulnerability scan or a penetration test, and it sends no attack traffic.
  5. 05The result is a point-in-time view of one response; a CDN rule or another page can send different headers.
FAQ

Questions about the headers check.

Why is Server: nginx flagged without a version?

Any Server or X-Powered-By header is rated low, because the name alone tells visitors which software runs the site. Remove the header or reduce it to a generic value if your platform allows it.

Why does the result differ from my server configuration?

The checker reads the response it receives after up to five redirects. Headers that a CDN, proxy or hosting platform adds or removes are the ones that count, and CDN, proxy or bot-protection rules can answer browsers differently than they answer the checker.

Can I check a site I do not own?

Yes. The header check reads one ordinary response that the site already sends to every visitor; the full run sends a few more ordinary requests for the other checks. Protected modules and full audits require a verified target or explicit authorization.

Is this a vulnerability scan?

No. It is a passive check of response headers, not a vulnerability scan or a penetration test, and it does not prove that a site is secure.