Security Headers Checker
See which HTTP security headers a website sends, what each one actually does, and whether any are misconfigured.
About this tool — and an important caveat
This checks for six commonly-recommended security headers and explains what each does. It is not a checklist where every header is mandatory for every site — a static marketing page with no user data and no embedded third-party content has a very different real risk profile than a bank's login page, and the right set of headers depends on what a specific site actually needs to protect. Treat "missing" as a prompt to evaluate whether that header would help your specific situation, not as an automatic failing grade.
"Configuration issue" vs. "missing"
A header can be present but effectively useless — set to a value browsers ignore, or a directive that provides no real restriction. This tool distinguishes that case specifically from a header that's absent entirely, since the fix is different: a missing header needs to be added, a misconfigured one needs its value corrected.
Related tools: