Free Security Headers Checker How safe are your headers?

Enter a website. We load it over HTTPS, read the response headers, and grade the six that protect visitors, with the line to add for each one that is missing.

How to check your headers

  1. Enter your website. The checker loads it over HTTPS, the way a browser would, and follows redirects.
  2. Read the grade and the six checks. Each says pass, weak or missing, with what the header does.
  3. Add what is missing using the examples below, then check again.

The six headers that make the grade

Strict-Transport-Security (HSTS) tells browsers to use HTTPS only, even when someone types http://.

Strict-Transport-Security: max-age=31536000; includeSubDomains

Content-Security-Policy (CSP) lists where scripts, styles, images and frames may load from. It is the strongest defence against cross-site scripting, and the hardest to get right.

Content-Security-Policy: default-src 'self'; script-src 'self' https://cdn.example.com; frame-ancestors 'self'

X-Frame-Options, or the CSP's frame-ancestors, stops other sites from loading your pages in a hidden frame and tricking people into clicking.

X-Frame-Options: SAMEORIGIN

X-Content-Type-Options stops browsers from guessing file types, so an uploaded file can never run as a script.

X-Content-Type-Options: nosniff

Referrer-Policy limits how much of your URLs other sites see when people follow a link away.

Referrer-Policy: strict-origin-when-cross-origin

Permissions-Policy turns off browser features your site doesn't use.

Permissions-Policy: camera=(), microphone=(), geolocation=()

How the grade works

Each header is worth one point, or half a point when it is set but weak (a short HSTS max-age, a CSP that allows inline scripts, a referrer policy that leaks full URLs). Six points over HTTPS is A+, five is A, four is B, three is C, two is D, and below that F.

The checker also looks at two things outside the grade: whether plain http:// redirects to HTTPS, and whether the Server or X-Powered-By header gives away a version number.

Where to set them

  • Nginx: add_header Strict-Transport-Security "max-age=31536000; includeSubDomains" always; in the server block.
  • Apache: Header always set X-Content-Type-Options "nosniff" in the config or .htaccess.
  • Cloudflare: Rules, then Transform Rules, then a response header rule.
  • Vercel and Netlify: a headers section in vercel.json or a _headers file.
  • Your app: most frameworks have middleware for security headers.

Rolling out a Content-Security-Policy safely

A strict CSP can block your own scripts, analytics and payment forms. Start with Content-Security-Policy-Report-Only: the browser reports what it would block but blocks nothing. Fix the sources it reports, then switch the header name. If you use NoirTrack, allow its script and API host in script-src and connect-src.

Headers protect visitors in the browser. The NoirTrack firewall works one step earlier and stops bad bots, scanners and attack traffic before it reaches your pages.

Questions, answered.

Response headers that tell the browser how to protect people on your site: always use HTTPS, which scripts may run, whether other sites may frame your pages, and more.

Strict-Transport-Security and Content-Security-Policy do the most. X-Content-Type-Options, frame protection, Referrer-Policy and Permissions-Policy are quick wins.

Six headers count, one point each, half a point when set but weak. Six points over HTTPS is A+, five is A, four is B, down to F.

The frame-ancestors rule in a Content-Security-Policy replaces it in modern browsers. The checker accepts either.

Strict-Transport-Security tells browsers to only ever use HTTPS for your site, for as long as max-age says. A year (31536000) is the usual value.

It can, if it leaves out a source your pages use. Start with Content-Security-Policy-Report-Only, fix what it reports, then switch to the real header.

A version number, like nginx/1.18.0, tells attackers which known bugs to try. Hide the version; it costs nothing.

Not directly, apart from HTTPS itself. They protect your visitors and your reputation, which is reason enough.

Try NoirTrack

Do this on every visit.

This tool checks one thing at a time. NoirTrack counts people, AI crawlers and bots on every visit, and blocks the ones you don't want.

Free 14-day trial, no credit card