Instantly check whether your site sends the security headers that matter most — CSP, HSTS, X-Frame-Options, X-Content-Type-Options, and Referrer-Policy. Free, no signup.
Free plan · 1 URL check at a timeThese 5 headers are a great baseline. Pair this with our SSL Checker to also confirm your certificate and TLS configuration are solid.
Run Free Website AuditHTTP security headers are instructions your server sends to every visitor's browser, telling it how to behave defensively — what content is allowed to load, whether the connection must stay encrypted, whether the page can be embedded in another site, and more. They cost nothing to add and take effect instantly, yet a huge share of sites still ship with most of them missing. This tool sends one live request to your URL, reads the actual response headers your server returns (following redirects to the final page), and evaluates five of the most widely recommended headers: Content-Security-Policy, Strict-Transport-Security, X-Frame-Options, X-Content-Type-Options, and Referrer-Policy. Each is scored on whether it's present and reasonably configured, rolled into a single 0–100 score, with the full raw header dump shown so you can verify exactly what we saw.
This is a deliberately focused baseline check, not a full security audit. It doesn't cover every possible header (such as Permissions-Policy or cookie security flags), and it doesn't evaluate your TLS/SSL certificate or encryption configuration — for that, pair this tool with our SSL Checker. Header requirements can also vary by site: a header that's essential for one type of site (like a strict CSP on a page with lots of third-party embeds) may need tuning rather than a blanket "on." Treat this as a fast way to catch obvious gaps, not a compliance certification.