Home About Support Blog Ask AI
Dashboards +
On-Page SEO +
Technical SEO +
SERP & Content +
Local SEO +
Get the Chrome Extension
Free Security Tool

Security Headers Checker

Analyze HTTP security headers, server configuration, and redirect chain for any URL. Get a security score with actionable recommendations.

Last updated: September 2026

What this security headers checker tests

A security headers checker catches the easiest exploits to prevent, and the ones sites forget most often. No HSTS? Users can be downgraded to HTTP. No CSP? You're wide open to XSS. No X-Frame-Options and no CSP frame-ancestors? Your pages can be framed for clickjacking.

This HSTS checker and CSP checker sends a HEAD request and audits 10 security headers, each weighted by real-world impact. CSP and HSTS count the most because they block the most common attack vectors. You also get the Server and X-Powered-By values and a 0-100 security score. Missing headers get a copy-ready value; headers that are present but weak get the specific reason, so a CSP with 'unsafe-inline' or an HSTS with a two-week max-age does not quietly pass.

What are security headers and why they matter

Security headers are HTTP response headers that tell the browser how to handle your site's content safely. They enforce HTTPS, block cross-origin framing, control script sources, and set referrer policy. Unlike most SEO issues, missing security headers don't slow your site down or hurt rankings directly. What they hurt is user trust and your audit scores with any security scanner.

Most common security header mistakes

The same gaps show up on most sites I audit. HSTS with a short max-age, which leaves anyone who hasn't visited recently unprotected, or without includeSubDomains, which leaves every subdomain on plain HTTP. A CSP that allows 'unsafe-inline' for scripts, which defeats the whole point of having a CSP. X-Content-Type-Options missing entirely, leaving MIME sniffing wide open. And the most common: no Content-Security-Policy at all because "it broke the site" and nobody went back to fix it properly.

OWASP recommendations for HTTP security headers

OWASP is the authoritative source for HTTP security header guidance. The OWASP Secure Headers Project maintains a reference list with recommended values for each header. The top five that almost every site should set: Strict-Transport-Security with a max-age of at least a year, a Content-Security-Policy, X-Content-Type-Options: nosniff, X-Frame-Options: DENY (or CSP frame-ancestors, which supersedes it in modern browsers), and Referrer-Policy: strict-origin-when-cross-origin. Set those five correctly and you've covered the majority of what OWASP actually asks for. Everything else is optional fine-tuning.

Explore more tools

FAQ

What is HSTS?+
HTTP Strict Transport Security tells browsers to only connect via HTTPS. Without it, a user who types your domain or follows an old http:// link makes that first request unencrypted, which is where downgrade attacks happen.
What is Content-Security-Policy?+
CSP controls which resources (scripts, styles, images) can be loaded on your page. OWASP calls it an added layer of defense against XSS: it limits the damage when escaping in your code fails, it doesn't replace that escaping.
What score should I aim for?+
A score of 80+ is good. 90+ is excellent. Focus on HSTS, CSP, and X-Content-Type-Options first. These provide the biggest security improvements.
Do security headers affect SEO?+
Only through HTTPS. Google uses HTTPS as part of its page experience signals, and HSTS makes browsers stick to it. Google has never said the other headers count for ranking. They protect your visitors, and a hacked site that gets flagged in search loses traffic fast.
What is the most important security header?+
This tool weights Content-Security-Policy highest (20 of 100 points) because it limits cross-site scripting (XSS), followed by HSTS (15) because it forces HTTPS. A CSP only helps if it's strict, though: one with 'unsafe-inline' for scripts barely helps.
Security headers on every page

Lumina checks HTTP status, security headers, and server info automatically — for free.

Add Lumina to Chrome — Free