Security headers checker
Check the HTTP security headers of a public website online. Enter a domain to see how eight key security headers are rated on the final response and, where shown, the value observed.
Validating the public target…
—
The HTTP security headers check is open first. The other seven passive checks from the same run are listed below it, closed.
Values are shortened and sanitized: IP addresses, cookie values, tokens and the name part of e-mail addresses are removed, and URLs are reduced to scheme and host.
Let your coding agent fix it, then re-test.
Carry this target into Sitelemetry, connect Codex or Claude, generate a bounded fix prompt and run the same checks again.
What each header does and how it is rated
The checker reads these headers on one response. Most rows are presence checks: a header that is sent counts, and its value is shown where available so you can judge whether it suits your site.
| Header | What it does | What good looks like | How this checker rates it |
|---|---|---|---|
Strict-Transport-Security | Makes returning browsers switch to HTTPS on their own, before any request leaves in plain HTTP. | A long max-age (180 days or more) once your ramp-up is done; the guide covers the stages. | Missing on an HTTPS target: medium. Not rated when you enter an http:// address. |
Content-Security-Policy | Gives the browser an allowlist of sources for the page's code and content. | A policy built from the resources your pages really use, without broad script exceptions. | Missing: medium. The value is shown but not reviewed. |
X-Frame-Options · frame-ancestors | Stops other sites from showing your page inside a frame of theirs. | frame-ancestors in your CSP, with X-Frame-Options as a fallback for older browsers. | Neither present: medium. |
X-Content-Type-Options | Makes the browser trust the declared content type of each response. | The single value nosniff. | Missing or any other value: low. |
Referrer-Policy | Limits which part of your page address other sites see when visitors follow your links. | A policy at least as strict as the current browser default. | Missing: low. |
Access-Control-Allow-Origin | Decides which other sites' scripts may read your responses. | Not sent on ordinary pages, or naming one trusted origin. | A wildcard (*): medium. |
Server · X-Powered-By | Announces the software behind the response. | Removed, or reduced to a generic value. | Any Server or X-Powered-By header: low, even without a version number. Only recognised technology names are shown. |
Set-Cookie | Sets cookies; its attributes decide which scripts can read them and when they are sent. | Session cookies hidden from scripts and sent over HTTPS only. | A cookie on this response without HttpOnly, or without Secure on HTTPS: medium. SameSite is not checked, and cookie values are never shown. |
Permissions-Policy and Cross-Origin-Opener-Policy are not rated on this page. The launch readiness snapshot counts them only in its separate hardening grade.
How to read each status.
- 01PassedThe header was found and meets the presence check.
- 02Low · Medium · HighSomething is missing or set in a way this check flags. The level is the same one the full snapshot uses.
- 03ObservedA value was recorded, but the check produced neither a pass nor a finding.
- 04Nothing observedThe check ran but there was nothing to record, for example no cookie on the response.
- 05Not applicableThe check does not apply, for example HSTS when you enter an http:// address.
- 06Not measuredNo usable response was received, so the check is not counted as passed.
What this checker does not do.
- 01It requests only the home page of the origin you enter. Paths and query strings are dropped, and no other page is requested.
- 02It mostly checks whether a header is present, not whether its value suits your site.
- 03It tests the HTTP to HTTPS redirect only when you enter the http:// address; that run skips TLS and does not report a missing HSTS header.
- 04It is not a vulnerability scan or a penetration test, and it sends no attack traffic.
- 05The result is a point-in-time view of one response; a CDN rule or another page can send different headers.
Questions about the headers check.
Why is Server: nginx flagged without a version?
Any Server or X-Powered-By header is rated low, because the name alone tells visitors which software runs the site. Remove the header or reduce it to a generic value if your platform allows it.
Why does the result differ from my server configuration?
The checker reads the response it receives after up to five redirects. Headers that a CDN, proxy or hosting platform adds or removes are the ones that count, and CDN, proxy or bot-protection rules can answer browsers differently than they answer the checker.
Can I check a site I do not own?
Yes. The header check reads one ordinary response that the site already sends to every visitor; the full run sends a few more ordinary requests for the other checks. Protected modules and full audits require a verified target or explicit authorization.
Is this a vulnerability scan?
No. It is a passive check of response headers, not a vulnerability scan or a penetration test, and it does not prove that a site is secure.