Security Header Check

Analyze your website's HTTP security headers and get recommendations to improve your security posture.

Enter any HTTPS URL to check its security headers

What We Check

Content-Security-Policy

Controls which resources can be loaded, preventing XSS attacks

Strict-Transport-Security

Forces HTTPS connections, preventing protocol downgrades

X-Frame-Options

Prevents clickjacking by controlling iframe embedding

X-Content-Type-Options

Prevents MIME-type sniffing attacks

Referrer-Policy

Controls how much referrer information is shared

Permissions-Policy

Restricts browser features and APIs