Security Headers Checker
Check which HTTP security headers a site sends.
About this check
HTTP security headers instruct browsers to enable protections: HSTS forces HTTPS, Content-Security-Policy limits script/style sources, X-Frame-Options blocks clickjacking, and X-Content-Type-Options stops MIME sniffing.
This tool fetches the site over HTTPS and reports which of the key security headers are present. Missing headers are quick, high-impact wins for most sites.
Frequently asked questions
Which header matters most?
HSTS and a strong Content-Security-Policy give the biggest security gains for browser-facing apps.
Can headers break my site?
A strict CSP needs testing, but HSTS, X-Frame-Options and X-Content-Type-Options are usually safe to add.
Want the full picture?
Get a complete security report with an exposure score across email, DNS, TLS, exposure and breach metadata.
Run a full report All tools