Security Headers Checker
See which security headers your site sends: HSTS, Content-Security-Policy, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, and Permissions-Policy. These headers help prevent XSS, clickjacking, and protocol downgrade—and are recommended by OWASP and browser security guidelines. Note: the Permissions-Policy response header is mainly enforced in Chromium; Firefox, Safari, and iOS WebView often ignore it, but sending it is still useful where it applies.
Enter your domain below. The report shows each header’s presence and value, plus SSL and redirect info in the same run. No signup.
Enter any domain — no signup, results in seconds.
User-Agent:
Related tools: