go-supertools
Security & Privacy Tools

Security Headers Auditor

Check which common security headers a website sends.

Looks up live data What you enter is sent to our server to fetch live results from public sources. Results are cached briefly.

About this tool

Enter a website address and the tool requests it from our server, following redirects, and checks for six response headers: Strict-Transport-Security, Content-Security-Policy, X-Frame-Options, X-Content-Type-Options, Referrer-Policy and Permissions-Policy. Each is marked present or missing and the grade is based on how many are present: 6 gives A+, 5 gives A, 4 gives B, 3 gives C, 2 gives D, and 0 or 1 gives F. It checks only that a header exists, not whether its value is a good one, and results are cached for about ten minutes.

How to use it

  1. Enter a URL such as example.com.
  2. Press Audit.
  3. Read which headers are present and the grade.
  4. Add the missing headers in your web server or CDN configuration and test again.

Common problems

Grade is low but the site seems secure
The grade only counts these six headers. A site can have other protections, and a high grade does not mean the header values are strong.
Header shows missing though you set it
You may have changed a different page or environment, or a cached result was shown. Wait a few minutes and retry with the exact URL.
Request fails
The site may block automated requests, time out, or use a non-standard port. Internal addresses are refused.