Security Headers Auditor
Check which common security headers a website sends.
Looks up live data What you enter is sent to our server to fetch live results from public sources. Results are cached briefly.
About this tool
Enter a website address and the tool requests it from our server, following redirects, and checks for six response headers: Strict-Transport-Security, Content-Security-Policy, X-Frame-Options, X-Content-Type-Options, Referrer-Policy and Permissions-Policy. Each is marked present or missing and the grade is based on how many are present: 6 gives A+, 5 gives A, 4 gives B, 3 gives C, 2 gives D, and 0 or 1 gives F. It checks only that a header exists, not whether its value is a good one, and results are cached for about ten minutes.
How to use it
- Enter a URL such as example.com.
- Press Audit.
- Read which headers are present and the grade.
- Add the missing headers in your web server or CDN configuration and test again.
Common problems
- Grade is low but the site seems secure
- The grade only counts these six headers. A site can have other protections, and a high grade does not mean the header values are strong.
- Header shows missing though you set it
- You may have changed a different page or environment, or a cached result was shown. Wait a few minutes and retry with the exact URL.
- Request fails
- The site may block automated requests, time out, or use a non-standard port. Internal addresses are refused.