Skip to content

HTTP Security Headers Checker

Grade a site's security headers and cookies and get the header lines to add.

Runs on the XGM server. Nothing is stored.

Headers are read from the final page after redirects. Press Enter to run. Try , , .

About this tool

Grade a site's security headers and cookies and get the header lines to add.

How to use it

  1. Open the HTTP Headers tool.
  2. Enter the public domain, hostname or IP address you want to check.
  3. Run the check; XGM queries it from its server and lists the findings.
  4. Copy the output only after checking it looks correct.
  5. Use related XGM tools if you need a broader diagnostic view.

FAQ

Is the HTTP Headers free to use?

Yes. The HTTP headers checker is free and works without creating an account.

Does XGM store my input for HTTP Headers?

Browser-side utilities process input locally. Server checks send only the domain, host or IP you enter to the XGM API and do not store it.

Can I use HTTP Headers for production checks?

Yes, use it for quick validation and troubleshooting. For critical changes, confirm the result with your official provider, logs, monitoring or security stack.

What should I do after using the HTTP headers checker?

Compare the result with related signals, save useful evidence and follow the linked XGM guide or related tools if you need a wider check.

Read the full HTTP Security Headers Checker guide

Further reading