Check HSTS, CSP, X-Frame-Options, X-Content-Type-Options, Permissions-Policy, Referrer-Policy and more — get a clear grade and fix recommendations. Free to use • No account required.
✍️ Author: ToolsNovaHub•📅 Last Updated: 13 September 2026•🔧 Methodology: live GET request via server-side proxy, max 10 redirects, 10s timeout, private/internal IPs blocked at every hop
Examples:
github.comcloudflare.com
🔄 Fetching response headers…
🏆 Security Grade
📊 Quick Stats
HTTP Status—
Final URL—
Headers Present—
Headers Missing—
✅❌ Header-by-Header Breakdown
Header
Status
Value
💡 Recommendations
🔎 All Raw Response Headers
🕒 Recent Checks
No recent checks yet.
📚 What Are HTTP Security Headers?
HTTP security headers are response headers a server sends that instruct the browser to enforce defensive behavior — restricting which scripts are allowed to run, blocking your page from being embedded in another site's iframe, forcing HTTPS-only connections, and limiting what data leaks to other origins. They cost nothing to add and require no code changes beyond server or CDN configuration, making them one of the highest-leverage security wins available. HSTS is defined in RFC 6797; Content-Security-Policy is a W3C specification.
⚙️ How This Checker Works
Browsers deliberately block JavaScript running on one site from reading response headers returned by another site (CORS), unless that site explicitly opts in — almost none do. So this tool performs the GET request through a small server-side proxy, reads the real response headers there, and returns them to your browser as JSON. This is the same approach every security-header-checking tool on the internet uses under the hood.
This proxy performs a single, standard GET request identical to what a normal visitor's browser sends when loading the page — it reads only the response headers already returned to any visitor, does not attempt to bypass authentication or access controls, and does not store the URLs checked. Only check domains you own or have permission to assess; this data is public by design, but repeated automated probing of a site you don't operate can still be flagged as unwanted traffic by that site's own security monitoring.
Allow-lists sources for scripts/styles/images — main XSS defense
X-Frame-Options
Blocks clickjacking by controlling iframe embedding
X-Content-Type-Options
Stops MIME-sniffing attacks (should be nosniff)
Referrer-Policy
Controls how much URL data leaks via the Referer header
Permissions-Policy
Restricts browser features like camera, mic, geolocation
Cross-Origin-Opener-Policy
Isolates your browsing context from cross-origin windows
Cross-Origin-Resource-Policy
Controls which sites can embed your resources
🏆 How the Grade Is Calculated
Each present, correctly configured header adds points; missing or weak configurations subtract points. HSTS, CSP, and a framing defense carry the most weight since they block the highest-impact attack classes (downgrade, XSS, clickjacking). The scale runs A+ down to F, mirroring the scoring philosophy used by well-known header-scanning services.
🔧 Troubleshooting
⚠️ Header added but still showing missing
Confirm the header is set on the actual response the browser receives — a CDN, reverse proxy, or caching layer in front of your origin server can strip or override headers your app code sets correctly.
⚠️ Grade dropped after a recent change
Check whether a CSP directive was tightened (or loosened) unintentionally, or whether a header was accidentally duplicated with conflicting values — browsers generally honor the first or most restrictive instance depending on the header.
⚠️ CSP header present but site functionality broke
A restrictive Content-Security-Policy can block legitimate inline scripts, fonts, or third-party embeds. Use your browser's console to see exactly which resource was blocked, then adjust the relevant directive rather than removing CSP entirely.
🛡️ Use Cases
🔧
Pre-Launch Checklist
Run this before shipping a new site or after a hosting/CDN migration to confirm security headers survived the move.
📊
Compliance & Audits
Many security questionnaires and PCI-adjacent checklists ask about header configuration — get a quick, shareable snapshot.
🔄
Regression Detection
Re-check periodically — a config change, CDN reset, or new reverse proxy can silently drop headers that used to be there.
🎯
Competitive Benchmarking
Compare your header grade against competitors or industry leaders to see what a mature security posture looks like in practice.
ToolsNovaHub tools are built and independently maintained with a focus on accurate, no-signup network and security utilities. Spotted an error? Let us know.
🎓
Expert Tip
A single scan from Security Headers Checker is a snapshot — security posture drifts as certificates near expiry or headers get overwritten by a new deploy, so schedule periodic re-checks.
⭐
ToolsNovaHub Pro Tip
Combine Security Headers Checker with our Website Security Scanner for one combined view covering TLS, headers, and email authentication together.
⚠️
Common Beginner Mistake
Assuming a perfect score from Security Headers Checker means the site is fully secure. It checks configuration, not application-layer bugs like SQL injection — pair it with a manual code review.
HTTP security headers are response headers a server sends that instruct the browser to enforce defensive behavior — restricting which scripts are allowed to run, blocking…
Is Security Headers Checker free to use? +
Yes, Security Headers Checker is free to use • no account required, and no hidden charges. It runs through our own server-side proxy, which applies a soft per-IP rate limit purely to prevent abuse — normal use won't come close to it.
What are HTTP security headers? +
Response headers that tell the browser to enforce defensive behavior — restricting scripts, blocking iframe embedding, forcing HTTPS, and limiting data leaks to other origins.
What is HSTS? +
Strict Transport Security forces the browser to only connect over HTTPS for a set duration, preventing SSL-stripping downgrade attacks.
What is Content-Security-Policy (CSP)? +
An allow-list of sources scripts, styles, and other resources may load from — one of the most effective defenses against XSS.
What does X-Frame-Options do? +
Controls whether your page can be embedded in an iframe elsewhere, preventing clickjacking attacks.
What is X-Content-Type-Options? +
Set to nosniff, it stops the browser from guessing content types, preventing certain disguised-file execution attacks.
What is Permissions-Policy? +
Controls which browser features — camera, microphone, geolocation, and more — the page and any embedded iframes may use.
What is Referrer-Policy? +
Controls how much URL information is sent as the Referer header when a user follows a link, reducing accidental data leakage.
Why does this tool need a server-side check? +
Browsers block JavaScript from reading another site's response headers unless that site opts in via CORS, which almost none do — so a small server-side proxy performs the check instead.
What is a good security headers score? +
A strong baseline covers HSTS, a restrictive CSP, X-Content-Type-Options: nosniff, a framing defense, and a non-default Referrer-Policy.
Do security headers replace a Web Application Firewall? +
No. Headers are free, browser-enforced instructions; a WAF filters malicious requests at the network edge. They're complementary, not substitutes.
Why does my site show Server or X-Powered-By headers? +
Many frameworks add these by default, revealing your stack. Removing or genericizing them is a minor hardening step.
How do I add security headers to my site? +
Add them via add_header/Header directives on Nginx/Apache, a headers config on Cloudflare/Vercel/Netlify, or a middleware like helmet for Express.
Is Security Headers Checker free? +
Yes — free, no sign-up. It performs a live GET request through a lightweight proxy and reports exactly what headers came back; the proxy applies a soft per-IP rate limit to prevent abuse, which normal usage won't hit.