Free security audit·A–F grade in seconds

Security headers checker with an A–F grade

Run a free security headers checker on any website: full response-header audit, HSTS and CSP checks, an A–F security grade, and clear fixes for missing headers — no signup needed.

Live fetch
Security header score
Enter a URL to fetch its HTTP headers.
Try github.com, cloudflare.com, or your own site.
What you get

See what attackers see, fix what matters

One audit grades your headers and tells you exactly what to add.

A–F security grade

Get an instant A–F grade summarising your header posture, so you can benchmark progress as you harden your site.

HSTS and CSP checks

Verify the headers that matter most — Strict-Transport-Security, Content-Security-Policy and more — with pass/fail detail on each.

Full response-header audit

Every response header is listed and explained, including the informational ones, so nothing hides in your server's replies.

Missing-header fixes

Each missing or weak header comes with the exact header to add, so your developers can implement fixes without research.

Stop second-guessing.

Find your domain in the next 30 seconds.

Free forever. No login required. 1,100+ TLDs in one query — plus AI suggestions and the premium marketplace.

1,147
TLDs
200ms
Avg lookup
100
Suggestions/query
FAQ

Security headers checker FAQs

Security headers are response directives that tell browsers how to behave — forcing HTTPS, blocking clickjacking, restricting scripts. Missing headers leave your site exposed to common attacks like cross-site scripting and protocol downgrade. Adding them is one of the cheapest security wins available.
The grade condenses your header audit into an A–F score. It weighs the presence and correctness of key headers like HSTS, CSP, X-Frame-Options and Referrer-Policy. A higher grade means browsers receive stronger instructions to protect your visitors.
Each failing check shows the exact header and value to add. Apply them in your web server configuration or application code, redeploy, then rescan to confirm the grade improves. Most headers are single lines — fixes often take minutes, not hours.
Run a scan and find the Strict-Transport-Security and Content-Security-Policy rows in the report. Each shows present or missing along with the current value, so you can confirm they're set and correctly configured.
Yes — an overly strict Content-Security-Policy can block legitimate scripts, styles or embeds. Add headers one at a time, test your pages, and use report-only mode for CSP first. Rescan after each change to keep your grade improving without breaking functionality.
Indirectly. Headers like HSTS enforce HTTPS everywhere, and HTTPS is a confirmed ranking signal. Security headers also prevent attacks that cause downtime or malware flags — both of which hurt rankings. Treat them as part of a healthy, trustworthy site.