Website Security Headers Checker
Test your website's security headers in seconds. Get a clear grade, see exactly which protections are missing, and fix them with copy-paste examples — free, no signup.
Check your headers now. Our free scan grades your security headers as part of a full seven-section report — vulnerabilities, malware, SEO and speed included.
No signup · Results in minutes · Plain-language report
What security headers are, in plain language
Every time someone visits your site, your server sends invisible instructions along with the page. Security headers are a set of those instructions that tell the visitor's browser how to behave safely: don't let other sites embed this page, only load scripts from approved sources, always use the encrypted connection, and so on.
Think of them as your site's first line of defense. They cost nothing, they don't slow anything down, and they block entire categories of attacks automatically. Yet a large share of small-business sites are missing most of them — which is exactly why automated attacks check for them first.
The 6 headers that matter most
- Strict-Transport-Security (HSTS). Tells browsers to only connect over HTTPS — stops attackers downgrading visitors to an unencrypted connection.
- Content-Security-Policy (CSP). Declares which sources may load scripts and images — the strongest defense against cross-site scripting (XSS).
- X-Frame-Options. Prevents other sites from embedding your pages in frames — blocks clickjacking attacks.
- X-Content-Type-Options. Stops browsers guessing file types — prevents attackers smuggling code inside innocent-looking files.
- Referrer-Policy. Controls how much of your page address is shared on outbound clicks — protects visitor privacy.
- Permissions-Policy. Switches off browser features you don't use (camera, microphone, geolocation) — less for attackers to abuse.
How the grading works
Our checker grades your headers on an A–F scale. The grade reflects which of the six headers are present and whether they're configured correctly — a misconfigured header (for example, HSTS with too short a duration) scores lower than a correct one.
What a low grade actually risks: automated attack tools probe for missing headers because each gap is a known shortcut. A missing Content-Security-Policy means any injected script on your pages runs without resistance. The grade shows how many free protections you're leaving on the table.
How to add missing headers
Choose the route that matches your setup. After making changes, rescan to confirm the new grade.
Apache (.htaccess) — add near the top of the file:
Header always set Strict-Transport-Security "max-age=31536000; includeSubDomains"
Header always set X-Frame-Options "SAMEORIGIN"
Header always set X-Content-Type-Options "nosniff"
Header always set Referrer-Policy "strict-origin-when-cross-origin"
Header always set Permissions-Policy "camera=(), microphone=(), geolocation=()"
Nginx — add inside your server block:
add_header Strict-Transport-Security "max-age=31536000; includeSubDomains" always;
add_header X-Frame-Options "SAMEORIGIN" always;
add_header X-Content-Type-Options "nosniff" always;
add_header Referrer-Policy "strict-origin-when-cross-origin" always;
add_header Permissions-Policy "camera=(), microphone=(), geolocation=()" always;
WordPress (no server access) — a reputable security plugin can send these headers for you; enable its "security headers" feature and verify with a rescan. Start with everything except a strict CSP, which needs tuning per site (see common mistakes below).
Content-Security-Policy deserves care: begin in report-only mode so violations are logged, not blocked, then tighten the policy once you know what your site legitimately loads.
Why headers alone aren't enough
A perfect header grade with an outdated plugin or an exposed database backup is still an exposed site. Headers are one layer — essential, but one layer. They don't patch vulnerable software, close exposed files, or remove malware that's already there.
That's why our free scan checks all seven sections in one run: active vulnerability testing, security headers, technology fingerprinting, malware and blocklist status, technical SEO, on-page SEO and speed. Fix the headers, then let the full report show you everything else.
Common mistakes to avoid
- CSP too permissive. A policy of default-src * looks like protection but allows everything — barely better than no policy.
- HSTS without an HTTPS redirect. HSTS only helps visitors who already reached you over HTTPS once. Keep the http→https redirect in place too.
- Short HSTS max-age. Values under a year offer little lasting protection; 31536000 seconds (one year) is the standard.
- Forgetting subdomains. Without includeSubDomains, your subdomains stay unprotected.
- Setting headers on the CDN but not the origin (or vice versa) — attackers will find the unprotected path. Verify the final, public response.
Get your header grade now. Run the free scan — headers plus the other six sections, one plain-language report.
Frequently asked questions
Do security headers affect SEO?
Indirectly, yes. HTTPS is a confirmed ranking signal and HSTS only works on HTTPS sites. More importantly, a hacked site loses rankings fast — headers are cheap prevention.
Do security headers slow down my site?
No. Headers are a few bytes sent with each response. HSTS can actually make repeat visits slightly faster by skipping the HTTP-to-HTTPS redirect.
How often should I recheck my headers?
After any server, CDN, or hosting change — those are the moments headers silently disappear. Otherwise, include a headers check in your regular monthly security scan.
Can adding security headers break my website?
A strict Content Security Policy can block legitimate scripts, embeds, or fonts if written too tightly — test on a staging site first. The other headers on this page are safe to add as shown.
What is a good security headers grade?
Aim for an A: all six key headers present and correctly configured. A B usually means one header missing or slightly misconfigured — still worth fixing, since attackers automate against exactly these gaps.
Are security headers enough to protect my site?
No — they're one layer. Headers stop entire classes of browser-based attacks, but they don't patch vulnerable software or close exposed files. Run the full scan to check everything else.