Home› Cybersecurity›Security Headers Checker
Cybersecurity tool

Security Headers Checker

Enter a public HTTPS URL to retrieve response headers and review common browser security controls against practical OWASP-style checks.

Check HTTP security response headers

Enter a public HTTPS URL to retrieve response headers and review common browser security controls against practical OWASP-style checks.

For safety, the checker only connects to public IPv4 addresses on ports 80/443 and revalidates redirects.
HTTP status—
Checks passed—
Needs review—
Final URL—
Header / controlStatusObserved valueWhy it matters

What this security headers checker reviews

The checker fetches the final public response headers and surfaces common browser security controls including Content-Security-Policy, Strict-Transport-Security, X-Content-Type-Options, Referrer-Policy and Permissions-Policy. It also shows framing and cross-origin headers that may be useful depending on the application.

Presence is not enough

A header can exist and still be weak, incompatible or unsafe. CSP requires directive-level review; HSTS should only be deployed after HTTPS is reliable; Permissions-Policy depends on the features the application needs. The table therefore uses “present/check” rather than claiming a missing or present header proves the site is secure.

Safe URL-fetching controls

Because a server-side header checker can otherwise be abused to probe internal services, this implementation accepts only HTTP/HTTPS, standard ports and hosts resolving to public IPv4 addresses. Redirect targets are revalidated before connection.

Use the result as a review checklist

Compare each observed value with your application's threat model and current browser guidance. Security headers are one layer of defence; they do not replace secure code, authentication, patching, TLS configuration or vulnerability management.

Frequently asked questions

Which security headers should every site have?
There is no universal list for every response type. Common browser-facing controls include CSP, HSTS on HTTPS sites, X-Content-Type-Options and Referrer-Policy, but configuration depends on application context.
Is X-Frame-Options still needed with CSP?
Modern CSP frame-ancestors can provide framing control. Some sites keep X-Frame-Options for compatibility, but the policies should not conflict.
Why does the checker block private IP addresses?
That restriction reduces server-side request forgery risk by preventing the tool from being used to query internal or local services.
Does passing these checks mean a site is secure?
No. Headers are only one part of web security, and even present headers need their values reviewed.