Security Tools
Security Headers Checker
Check whether a website sends the common baseline HTTP security headers, and see what each one protects against.
How it works
This tool sends a real HTTP request to the address you enter. It checks the response for six commonly recommended security headers. For each one, it explains what it does and what it means if the header is missing.
FAQ
- Which headers does this check?
- This tool checks six commonly recommended baseline headers: Strict-Transport-Security, Content-Security-Policy, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, and Permissions-Policy. It only checks this specific set. It's not a full security audit.
- Does a header being "missing" mean the site is insecure?
- Not on its own. These headers add extra layers of defense, and each one blocks one specific type of attack. Some sites reasonably skip a header that doesn't apply to them. For example, a plain static site with no user input needs a strict CSP less than other sites do. Treat this as a checklist worth understanding, not a pass-or-fail grade.
- How is this different from the HTTP Headers Checker?
- Both tools make the same live request. This one filters the results down to just the headers that matter for security, and explains what each one does.