Check your website security headers
HTTP headers are a site's first, quiet line of defence. Enter an address and we check the most important ones (HSTS, CSP, X-Frame-Options and more), give a grade and show how to enable the ones that are missing.
We only check publicly visible response headers, like a browser. We do not log addresses.
Why do security headers matter?
They are instructions the server sends the browser on every visit. Set well, they hinder a whole class of attacks: session hijacking, impersonation, injection of foreign scripts or eavesdropping on an unsecured network. They cost nothing, you just have to enable them. Enter an address above and we show where your site stands and what to add.