Free Security Headers Checker

Get an A-F grade on your site's HTTP security headers, including CSP, HSTS, and cross-origin isolation policies.

Frequently asked

Which headers do you check?

Content-Security-Policy, Strict-Transport-Security (HSTS), X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, Cross-Origin-Opener-Policy, and Cross-Origin-Embedder-Policy.

How is the grade computed?

Each header carries a weight based on impact. Present headers earn their weight; the total is normalized to 0-100 and mapped to A through F.

Related tools

  • Email Security Checker · Check your domain's email authentication · SPF, DKIM, and DMARC · and see if you're vulnerable to spoofing.
  • DNS Security Checker · Check whether a domain is protected by DNSSEC and restricts certificate issuance with CAA records · two defenses against DNS hijacking and rogue certificates.
  • DNS Lookup · Query any domain's DNS records live · A, AAAA, CNAME, MX, TXT, NS, and CAA · resolved over encrypted DNS-over-HTTPS.

Run a full security scan →