How to check your headers
- Enter your website. The checker loads it over HTTPS, the way a browser would, and follows redirects.
- Read the grade and the six checks. Each says pass, weak or missing, with what the header does.
- Add what is missing using the examples below, then check again.
The six headers that make the grade
Strict-Transport-Security (HSTS) tells browsers to use HTTPS only, even when someone types http://.
Strict-Transport-Security: max-age=31536000; includeSubDomains
Content-Security-Policy (CSP) lists where scripts, styles, images and frames may load from. It is the strongest defence against cross-site scripting, and the hardest to get right.
Content-Security-Policy: default-src 'self'; script-src 'self' https://cdn.example.com; frame-ancestors 'self'
X-Frame-Options, or the CSP's frame-ancestors, stops other sites from loading your pages in a hidden frame and tricking people into clicking.
X-Frame-Options: SAMEORIGIN
X-Content-Type-Options stops browsers from guessing file types, so an uploaded file can never run as a script.
X-Content-Type-Options: nosniff
Referrer-Policy limits how much of your URLs other sites see when people follow a link away.
Referrer-Policy: strict-origin-when-cross-origin
Permissions-Policy turns off browser features your site doesn't use.
Permissions-Policy: camera=(), microphone=(), geolocation=()
How the grade works
Each header is worth one point, or half a point when it is set but weak (a short HSTS max-age, a CSP that allows inline scripts, a referrer policy that leaks full URLs). Six points over HTTPS is A+, five is A, four is B, three is C, two is D, and below that F.
The checker also looks at two things outside the grade: whether plain http:// redirects to HTTPS, and whether the Server or X-Powered-By header gives away a version number.
Where to set them
- Nginx:
add_header Strict-Transport-Security "max-age=31536000; includeSubDomains" always;in the server block. - Apache:
Header always set X-Content-Type-Options "nosniff"in the config or.htaccess. - Cloudflare: Rules, then Transform Rules, then a response header rule.
- Vercel and Netlify: a
headerssection invercel.jsonor a_headersfile. - Your app: most frameworks have middleware for security headers.
Rolling out a Content-Security-Policy safely
A strict CSP can block your own scripts, analytics and payment forms. Start with Content-Security-Policy-Report-Only: the browser reports what it would block but blocks nothing. Fix the sources it reports, then switch the header name. If you use NoirTrack, allow its script and API host in script-src and connect-src.
Headers protect visitors in the browser. The NoirTrack firewall works one step earlier and stops bad bots, scanners and attack traffic before it reaches your pages.