Security Headers Checker
Scan any website's HTTP security headers — CSP, HSTS, X-Frame-Options, Referrer-Policy and more — with grading and one-click fixes.
HTTP response headers are the browser's instruction manual for how to render your site safely. Miss a header and clickjacking, XSS, mixed content or downgrade attacks become one-click exploits. This checker grades every header a modern browser respects and shows the exact value to ship — no guessing, no theory.
Security Headers Checker evaluates the following signals from your target host:
Frequently asked questions
- Yes, unlimited scans and no signup required.
- Reports are cached in your browser only. Nothing is shared.
Related guides & resources
headers
Why Your Website Needs HSTS in 2026
One header, one config line, and downgrade attacks stop reaching your users. If your site doesn't ship HSTS in 2026, you're leaving free security on the table.
Read
headers
How to Roll Out CSP in Report-Only Mode
CSP is one of the most effective XSS defenses ever shipped — and one of the most feared to deploy. Report-only mode turns a scary launch into a boring one.
Read
dns
DMARC in Plain English
SPF, DKIM, DMARC. Three DNS records, one goal: stop other people from sending email as you. Here is what each one actually does — and how to turn them on without losing legitimate mail.
Read