Security Headers Checker
Inspect the security headers returned by a public website and find configuration improvements.
01
Website URL
How it works
Reads the headers of one public HTTP response, following up to three redirects. The six checks cover CSP, HSTS, MIME sniffing, framing, referrer disclosure and browser permissions. Header coverage is an observation, not a certification or a vulnerability scan.
Results may differ by URL, CDN, status code, user agent or geography. A block page is not your application response. Examples are starting points: adapt and test them against your application before deployment. The submitted URL is requested from our server; private addresses and custom ports are excluded.