Search tools

Search for a command to run...

HTTP Security Headers Checker

Paste a site's HTTP response headers to grade its security headers — HSTS, CSP, X-Content-Type-Options, clickjacking protection, Referrer-Policy and Permissions-Policy.

How to use

  1. 1Get the headers: run curl -sI https://example.com, or open DevTools → Network → click the page → Response Headers → copy.
  2. 2Paste them here to see the grade and what to fix.

How it's calculated

Each header is weighted (HSTS 25, CSP 25, clickjacking 15, nosniff 10, Referrer-Policy 10, Permissions-Policy 10, no version leaks 5). Grade: A ≥ 90, B ≥ 75, C ≥ 60, D ≥ 40, otherwise F.

Frequently asked questions

Why paste headers instead of entering a URL?

Browsers block pages from reading other sites' headers. Pasting keeps the check private and works for internal sites too.

Which header matters most?

A strict Content-Security-Policy and HSTS give the biggest protection — against script injection and HTTPS downgrade attacks.

Is X-XSS-Protection still needed?

No — modern browsers removed the XSS auditor. Use a Content-Security-Policy instead.