Security Headers Checker

Audit HTTP response security headers against best practices — HSTS, CSP, X-Frame-Options, X-Content-Type-Options and more. Paste raw headers from DevTools, or try a live fetch, and get an instant security grade with fix suggestions. No signup required.

Option 1: Live Check

Note: the browser may block cross-origin header reads. If that happens, use Option 2 below.

Option 2: Paste Raw Headers

Need something more powerful?

Custom APIs, dashboards, automations — whatever you need.

Start a Project →