Security header checker
Check which browser security headers a website sends (HSTS, CSP, X-Content-Type-Options, Referrer-Policy and Permissions-Policy) and what they do.
Choosing a check opens its page. With the keyboard, use the arrow keys, then press Enter.
What we check
Security headers tell browsers to switch on protections for a site. We look at five widely used ones on the final page after redirects: Strict-Transport-Security (HSTS), Content-Security-Policy (CSP), X-Content-Type-Options, Referrer-Policy and Permissions-Policy. For each one we show its value, what it does, and anything its specification says is invalid or weak.
There is no score. Which headers a site needs depends on what it does, and headers are only one layer of protection, so their presence doesn't prove a site is secure.
A sensible starting point
Strict-Transport-Security: max-age=31536000; includeSubDomains, once every subdomain works over HTTPS.X-Content-Type-Options: nosniff.Referrer-Policy: strict-origin-when-cross-origin(the browser default) or stricter.- A Content-Security-Policy that uses nonces or hashes for scripts rather than
'unsafe-inline', withobject-src 'none'andbase-uri 'self'. Test it as Content-Security-Policy-Report-Only first.
Frequently asked questions
Is there a score or grade?
No. Which headers a site needs depends on what it does, and a grade can suggest a site is secure when headers are only one layer of protection. We show what each header does, its value, and anything its specification says is weak or wrong.
Which page is checked?
The final page after any redirects, because that is the page browsers show. The result says which address that was.
Why is HSTS ignored on my site?
Browsers only accept Strict-Transport-Security on an HTTPS response. If the final page is plain HTTP, the header has no effect.
Why is unsafe-inline flagged in my CSP?
With 'unsafe-inline' and no nonce or hash, any inline script that an attacker manages to inject will run, which removes most of the protection a policy gives. Using nonces or hashes switches 'unsafe-inline' off in modern browsers.
Is a missing Permissions-Policy a problem?
Not by itself. It is optional: it lets a site switch off browser features it doesn't use, such as the camera or location. We note it as information, not a problem.
Related tools
-
HTTP Header Checker
See the HTTP status and every response header a website sends, for the final page and each redirect on the way.
-
SSL Certificate Checker
Check whether a site's HTTPS certificate is valid and trusted, which names it covers, and when it expires.
-
Redirect Checker
Follow a web address through every redirect, with the status code, destination and timing of each hop.
-
Website Down Checker
Check whether a website is responding right now, from our server: status, response time, redirects, IP addresses and HTTPS.
-
DNS Lookup
Look up the DNS records published for a domain, one type or all common types at once, or the reverse DNS name of an IP address.
-
MX Lookup
See which mail servers receive email for a domain, in priority order, with each server's addresses.
-
SPF Checker
Check that a domain's SPF record is valid, stays within the 10-lookup limit, and says what you expect about servers that may send its mail.
-
DMARC Checker
Find the DMARC policy that applies to a domain, see what each setting means, and spot mistakes that make receivers ignore it.
-
Website Health Check
Run the main website, DNS and email checks on one site at once and get a short report, area by area, with links to the full results.