Domain & WebsiteFree · no sign-up

Security headers checker

Check which HTTP security headers a site sends: Strict-Transport-Security, Content-Security-Policy, X-Content-Type-Options, X-Frame-Options, Referrer-Policy and Permissions-Policy. Each one is graded with what it protects against and the exact header to add.

Loading the tool…

How to use the HTTP Headers & Status Checker

  1. 1Enter the URL you want to inspect.
  2. 2Read the status code, redirect count, response time and security score at the top.
  3. 3Open Headers for the full list, Security for graded security headers and cookies, or Redirects for each hop.
  4. 4Copy the headers to share them with your developer or hosting support.

Frequently asked questions

Which security headers should every website have?

Strict-Transport-Security, X-Content-Type-Options: nosniff, X-Frame-Options or a CSP frame-ancestors rule, and a Referrer-Policy. A Content-Security-Policy and Permissions-Policy add more protection but need testing.

Do security headers affect SEO?

Not directly as a ranking factor. HTTPS and HSTS protect visitors and trust, and a hacked or injected site loses rankings fast, so security headers protect your search traffic indirectly.

Can a Content-Security-Policy break my site?

Yes: a strict policy blocks any script, style or embed you didn't list. Start with Content-Security-Policy-Report-Only to see what would be blocked, then switch to enforcing.

All tools

Then schedule it with Join Postly

Plan, publish and track your posts on every network from one calendar. Free plan, no credit card.

No credit card required Free forever plan Cancel anytime