Skip to content
Approvalens

Free · no sign-up

Security Headers Checker

We fetch the page, list every response header it sends and go through the six security headers one by one: what's set, what's missing or weak, and what the browser does with it. No letter grade, just what each header does on your site.

Test a live site

The six headers we check

  • Strict-Transport-Security (HSTS): tells browsers to use HTTPS only for this host from now on. Browsers ignore it when it arrives over plain http.
  • Content-Security-Policy (CSP): limits where scripts, styles, frames and other resources may load from. The Report-Only version only reports violations and blocks nothing.
  • X-Content-Type-Options: nosniff is the only valid value. It stops the browser guessing a file's type, and makes it refuse scripts and stylesheets served with the wrong type.
  • X-Frame-Options or CSP frame-ancestors: stops other sites from loading your pages in a frame (clickjacking). X-Frame-Options does nothing in a meta tag; it must be a header.
  • Referrer-Policy: how much of the page address is sent to other sites in the Referer header.
  • Permissions-Policy: switches off browser features the site doesn't use, such as the camera, microphone or location.

How to read the result

OK means the header is set and does its job. Fix means it's missing or weak in a way worth changing. Note means it's optional or a judgement call: a CSP that allows inline scripts, a report-only policy, or no Referrer-Policy when the browser default is already reasonable.

The verdicts use the same rules as the security section of the full report. HSTS counts as short under 180 days; MDN notes that HSTS preloading needs at least one year (31536000 seconds) plus includeSubDomains.

Common fixes

  • nginx: add_header lines in the server block, with the always parameter so they're sent on error pages too. Example: add_header X-Content-Type-Options "nosniff" always;
  • Apache: Header always set lines in the virtual host or .htaccess (mod_headers must be enabled).
  • Cloudflare: HSTS has its own switch on the SSL/TLS > Edge Certificates page.
  • Start a CSP in Report-Only mode, read the reports for a while, then switch the same policy to Content-Security-Policy.
  • Send HSTS only once every subdomain works over HTTPS if you add includeSubDomains. Browsers remember it for max-age seconds.

What these headers don't do

Headers make some attacks harder in the browser. They don't patch an outdated plugin, a weak password or a vulnerable server. AdSense and Google Search don't publish any requirement for these headers; they're about protecting visitors and your own site.

Questions

Frequently asked questions

Why no letter grade?

A grade hides the part that matters: which header is missing and whether you need it. A small blog without logins gets far less from a strict CSP than a shop does. We show each header and let you decide.

Do I need all six?

HSTS, nosniff and frame protection are cheap to add and rarely break anything. CSP takes work to get right. Referrer-Policy is optional because browsers default to strict-origin-when-cross-origin, and Permissions-Policy is optional for sites that don't use those features.

I added the header but the checker doesn't see it. Why?

Common reasons: the server wasn't reloaded, the header is set only on some locations or only for 200 responses (nginx without always), a CDN cache still serves the old response, or a meta tag was used where only a header works.

Which page should I check?

Start with the homepage, then a post and any login or checkout page. Headers can differ per path when a plugin or a location block sets them.

Guides

Guides that use this tool

Where this check comes up, and how to fix what it finds.

Next step

One check here, the whole site in the report

This is one of 258 checks. Scan the whole site for the full picture; the first 50 pages are free.

First 50 pages free · no sign-up · no card