HTTP Security Headers Checker
Paste a site's HTTP response headers to grade its security headers — HSTS, CSP, X-Content-Type-Options, clickjacking protection, Referrer-Policy and Permissions-Policy.
How to use
- 1Get the headers: run curl -sI https://example.com, or open DevTools → Network → click the page → Response Headers → copy.
- 2Paste them here to see the grade and what to fix.
How it's calculated
Each header is weighted (HSTS 25, CSP 25, clickjacking 15, nosniff 10, Referrer-Policy 10, Permissions-Policy 10, no version leaks 5). Grade: A ≥ 90, B ≥ 75, C ≥ 60, D ≥ 40, otherwise F.
Frequently asked questions
Why paste headers instead of entering a URL?
Browsers block pages from reading other sites' headers. Pasting keeps the check private and works for internal sites too.
Which header matters most?
A strict Content-Security-Policy and HSTS give the biggest protection — against script injection and HTTPS downgrade attacks.
Is X-XSS-Protection still needed?
No — modern browsers removed the XSS auditor. Use a Content-Security-Policy instead.