Security Headers Check
Enter an address, check its HTTP security headers: a grade from A to F with concrete recommendations for every check.
This check is purely passive and observational - it only sees what any browser or search engine crawler already sees. No active security testing or access to internal systems takes place.
One address, one grade from A to F.
Enter the address of a publicly reachable website. The check evaluates the HTTP security headers of the response and shows a grade with concrete recommendations immediately, free and without sign-up.
FAQ
Is this an active security test?
No. The check retrieves the page like an ordinary browser and evaluates only the HTTP headers returned. It does not actively probe for vulnerabilities or test forms or credentials.
Which headers are checked?
Content-Security-Policy, Strict-Transport-Security, X-Content-Type-Options, clickjacking protection, Referrer-Policy, Permissions-Policy, the HTTP-to-HTTPS redirect, version disclosure in server headers, and the security attributes of any cookies set.
Is my input stored?
Checked addresses are only processed for the duration of the check and are not stored. Only if you request the detailed assessment by email do we send your input to us to process that request.