HTTP Security Headers Checker
Grade a site's security headers and cookies, get the header lines to add, and build a Content-Security-Policy that the same check approves.
Related tools
- TLS CheckerInspect a site's TLS certificate, expiry, issuer and negotiated protocol, with a renewal calendar you can download and a full report.
- Redirect CheckerTrace redirects from http and https, with and without www, to the final URL and spot loops and extra hops.
- SEO MetadataCheck a page's title, description, canonical, robots and Open Graph tags.
- Domain HealthOne check for DNS, email authentication, TLS, security headers and redirects, with a grade per area and a full report.
About this tool
HTTP Headers requests your page over HTTPS, follows the redirects and reads the response headers of the page that finally answers. It scores the six headers that protect visitors - Strict-Transport-Security, Content-Security-Policy, X-Content-Type-Options, X-Frame-Options, Referrer-Policy and Permissions-Policy - checks the Secure, HttpOnly and SameSite flags of every cookie, and gives you the configuration lines for nginx, Apache, Caddy and Cloudflare. Under the Content-Security-Policy finding it also builds a policy from the origins you name and runs that policy back through the same analysis, so the builder cannot hand you a header this page would criticise. It reads one URL as an anonymous visitor: it does not log in, execute JavaScript, crawl the site or judge the page content, and the builder runs entirely in your browser.
The domain you enter is sent to the XGM API, which requests https://<domain> from the XGM server with the User-Agent XGM-Web-Checks/1.0, follows up to six redirects with a 5 second timeout per hop and reads the response headers and Set-Cookie lines of the page that finally answers. The site you check sees the XGM server, not your browser; no JavaScript is executed, no page body is scored and nothing is stored with the result.
The same connection reports the TLS version, cipher and certificate above; the full certificate and protocol scan is the TLS Checker. The CSP builder under the Content-Security-Policy finding is a separate thing: it runs in your browser, the origins you type there are never sent anywhere, and the policy it writes is checked by the same analysis this page runs on a real header.
How to use it
- Open the HTTP Headers tool.
- Enter the public domain, hostname or IP address you want to check.
- Run the check; XGM queries it from its server and lists the findings.
- Copy the output only after checking it looks correct.
- Use related XGM tools if you need a broader diagnostic view.
FAQ
Which headers are counted in the score?
The six listed above. Cache-Control, cookie flags and the remaining response headers are reported as separate findings, because the right value depends on whether the page is public or personalised.
My CSP is there but still flagged. Why?
A policy that allows ‘unsafe-inline’ or ‘unsafe-eval’ in script-src, or falls back to a wildcard, does not stop the injection it is meant to stop. The finding names the directive that weakens the policy so you can replace it with a nonce or a hash.
Can I write a CSP here instead of copying one?
Yes. The builder under the Content-Security-Policy finding asks which origins the page loads scripts, styles, images, fonts, frames and XHR from, whether it needs inline styles or inline scripts, and whether you want ‘strict-dynamic’ with a nonce, and writes the header, the nginx line and the Apache line. It then runs the policy it just wrote through the same analysis this page runs on a real header, so anything it produces that would be criticised is criticised on the spot. Send it as Content-Security-Policy-Report-Only first, which is the default: an enforced policy that misses one origin breaks the page for every visitor.
How long should max-age be in HSTS?
At least 15,552,000 seconds (180 days) for a normal site, and 31,536,000 (one year) with includeSubDomains and preload if you want to submit the domain to the preload list. Start short while you confirm every subdomain works over HTTPS: browsers remember the value, so a long max-age is hard to take back.
Why do the headers differ from what my server config says?
The check reports the final response after redirects, so a CDN, a reverse proxy or a WAF in front of your origin can add, replace or drop headers on the way out. Compare the Final URL in the result with the host you configured.
Does a missing header mean the site is vulnerable?
No. These headers are defence in depth: they reduce the damage of a bug elsewhere, they do not prove one exists. A site without them can be safe, and a site with all six can still have an application vulnerability.
Read the full HTTP Security Headers Checker guide