Security Headers Checker

Grade a site's HTTP security headers: HSTS, CSP, X-Frame-Options, Referrer-Policy and more.

What are security headers?

Security headers are HTTP response headers that tell browsers how to behave when handling a site — for example to always use HTTPS, block clickjacking or restrict where scripts can load from — reducing the risk of common attacks.

Headers checked and recommended values

HeaderRecommended value
Strict-Transport-Securitymax-age=31536000; includeSubDomains
Content-Security-PolicyA policy listing allowed sources, without 'unsafe-inline' or 'unsafe-eval' where possible
X-Frame-OptionsSAMEORIGIN (or CSP frame-ancestors)
X-Content-Type-Optionsnosniff
Referrer-Policystrict-origin-when-cross-origin
Permissions-Policycamera=(), microphone=(), geolocation=()

The checker also warns when headers such as Server or X-Powered-By reveal software version numbers.

How the grade works

Each header earns points weighted by its impact: HSTS and CSP count most. A+ needs every important header set correctly; a missing CSP alone usually limits the grade to B.

How to add headers

Set them in your web server (Apache Header set, nginx add_header), your CDN, or your application. Test CSP in report-only mode first so it does not break your site.

Frequently asked questions

Do security headers affect SEO?

Not directly. They protect users, and HTTPS (enforced by HSTS) is a confirmed lightweight ranking signal.

Will adding a Content-Security-Policy break my site?

It can if it is too strict. Start with Content-Security-Policy-Report-Only, review the reports, then enforce it.

Is X-XSS-Protection still needed?

No. Modern browsers removed the XSS auditor, so a Content-Security-Policy is the right protection today.