HTTP Header Security Check
Fetch and review the security headers of any public website.
Requests the headers a website returns and highlights security-relevant ones: HSTS, CSP, X-Frame-Options, Referrer-Policy and more. The request is made server-side with SSRF protections and a short timeout.
The request is made from our servers with SSRF protection. Your IP is never revealed to the target site.
Privacy: Your IP is never sent to the target site — the request originates from our servers.
Related tools
Frequently asked questions
Which URLs can I check?
Any public HTTP or HTTPS URL. Private, local and metadata addresses are blocked by SSRF protection.