HTTP Header Security Check

Fetch and review the security headers of any public website.

Requests the headers a website returns and highlights security-relevant ones: HSTS, CSP, X-Frame-Options, Referrer-Policy and more. The request is made server-side with SSRF protections and a short timeout.

The request is made from our servers with SSRF protection. Your IP is never revealed to the target site.

Privacy: Your IP is never sent to the target site — the request originates from our servers.

Related tools

Frequently asked questions

Which URLs can I check?

Any public HTTP or HTTPS URL. Private, local and metadata addresses are blocked by SSRF protection.