Security headers checker
Check which HTTP security headers a site sends: Strict-Transport-Security, Content-Security-Policy, X-Content-Type-Options, X-Frame-Options, Referrer-Policy and Permissions-Policy. Each one is graded with what it protects against and the exact header to add.
How to use the HTTP Headers & Status Checker
- 1Enter the URL you want to inspect.
- 2Read the status code, redirect count, response time and security score at the top.
- 3Open Headers for the full list, Security for graded security headers and cookies, or Redirects for each hop.
- 4Copy the headers to share them with your developer or hosting support.
Frequently asked questions
Which security headers should every website have?
Strict-Transport-Security, X-Content-Type-Options: nosniff, X-Frame-Options or a CSP frame-ancestors rule, and a Referrer-Policy. A Content-Security-Policy and Permissions-Policy add more protection but need testing.
Do security headers affect SEO?
Not directly as a ranking factor. HTTPS and HSTS protect visitors and trust, and a hacked or injected site loses rankings fast, so security headers protect your search traffic indirectly.
Can a Content-Security-Policy break my site?
Yes: a strict policy blocks any script, style or embed you didn't list. Start with Content-Security-Policy-Report-Only to see what would be blocked, then switch to enforcing.
Related free tools
All tools- HTTP Headers & Status CheckerStatus code, response headers and security headers of any URL.
- HTTP status code checkerHTTP status code checker
- Redirect Chain CheckerFollow every hop of a redirect, see 301s and 302s, and spot loops.
- Is It Down CheckerIs a website down for everyone or just you? Checked from Cloudflare.
- SSL Certificate CheckerIs HTTPS set up right? Certificate accepted, redirects, HSTS and CAA.
- Website SEO ScoreA free mini audit of one page with the Site Audit's checks and fixes.
Then schedule it with Join Postly
Plan, publish and track your posts on every network from one calendar. Free plan, no credit card.