Security headers: what does your site tell browsers?
Enter your site's address and see which security headers its home page sends: HSTS, content security policy, framing protection and the rest, each with what it is for and what to set.
What the headers check covers
- HTTPS and redirect
- Whether the page is served over HTTPS, and whether the plain-HTTP address redirects there.
- Strict-Transport-Security (HSTS)
- Whether browsers remember to open the site only over HTTPS, and for how long.
- Content-Security-Policy (CSP)
- Whether the site restricts where scripts may be loaded from: the strongest defence against injected scripts (XSS).
- Framing protection
- Whether other sites may show this page in a frame (X-Frame-Options or frame-ancestors); protects against clickjacking.
- X-Content-Type-Options
- Whether the browser is forbidden to guess the type of files.
- Referrer-Policy and Permissions-Policy
- What the site tells other sites about its visitors, and which browser features it allows.
- Cookies and software details
- Whether cookies carry their protective attributes, and whether the server gives away the version of its software.
Frequently asked questions
What are security headers?
With every answer a web server sends the browser instructions the visitor never sees. Security headers are the ones that tell the browser what not to allow: opening the site unencrypted, for example, or loading scripts from elsewhere. They protect the visitor, not the server.
Where do I set them?
In the web server's configuration: in the .htaccess file for Apache ("Header always set …"), in the server block for nginx ("add_header …"). WordPress and other systems have plugins for it. If the site is behind Cloudflare, they can be added there as well.
Can a header break my site?
Most cannot. Be careful with two: a content security policy can block scripts the site uses, so try it in report-only mode first; and HSTS forces visitors onto HTTPS for the time you give, so enable it only once certificate renewal works reliably.
What does the grade mean?
How many of the six main protections are in place. "A" means all of them are; it does not mean the site cannot be attacked. The grade is about the home page's headers and does not look for flaws in the web application.
Have a question about the results, or need help fixing something? Contact our support