HTTP Header Checker with Security Grade
This HTTP header checker shows every response header a server sends for an address – from Content-Type and Cache-Control to Set-Cookie – and grades the security headers against OWASP recommendations from A to F. Each gap comes with the header value to add.
Source: OWASP – HTTP Security Response Headers Cheat Sheet. Updated: .
How it is calculated
Security headers at a glance
| Header | Protects against | Recommended value (OWASP) |
|---|---|---|
| Strict-Transport-Security | Eavesdropping, downgrade to http:// | max-age=63072000; includeSubDomains |
| Content-Security-Policy | Cross-site scripting, foreign scripts | site-specific, e.g. default-src 'self' |
| X-Content-Type-Options | MIME sniffing | nosniff |
| X-Frame-Options or frame-ancestors | Clickjacking | DENY or frame-ancestors 'none' |
| Referrer-Policy | Leaking full URLs | strict-origin-when-cross-origin |
| Permissions-Policy | Abuse of camera, microphone, location | geolocation=(), camera=(), microphone=() |
| Cross-Origin-Opener-Policy | Attacks via opened windows | same-origin |
The checker also flags Server or X-Powered-By headers that reveal version numbers, and cookies set without Secure, HttpOnly or SameSite. The deprecated X-XSS-Protection header is listed as info only – OWASP advises setting it to 0 or leaving it out.
How the grade is calculated
HSTS and Content-Security-Policy are worth 20 points each; X-Content-Type-Options, clickjacking protection, Referrer-Policy, version disclosure and cookies 10 each; Permissions-Policy and Cross-Origin-Opener-Policy 5 each. A pass earns full points, “review” half, missing nothing. The percentage becomes a grade: A from 90 %, B from 75 %, C from 60 %, D from 45 %, E from 30 %, F below. The weighting is our own judgment based on the OWASP HTTP Headers Cheat Sheet.
Setting headers yourself
- Apache: in .htaccess, e.g.
Header always set X-Content-Type-Options "nosniff"(mod_headers). - nginx: in the server block,
add_header X-Content-Type-Options "nosniff" always; - CDNs and hosts: Cloudflare, Netlify and others offer settings or a _headers file.
Roll out a Content-Security-Policy as Content-Security-Policy-Report-Only first and enforce it once nothing legitimate would be blocked. Only enable HSTS when the site – and with includeSubDomains every subdomain – runs on HTTPS for good.
Limitations
You see the headers returned to our request from a Cloudflare data center. Some servers answer browsers, other countries or logged-in users with different headers. Cookie values are never passed on: only names and attributes are shown.
Frequently asked questions
How do I check the HTTP headers of a website?
Enter the address and click “Check headers” – the “All headers” table lists each header with its value. In your browser you can also open the developer tools (F12), go to the Network tab, click the request and choose “Headers”.
Which security headers should every website have?
At a minimum Strict-Transport-Security, X-Content-Type-Options: nosniff, clickjacking protection (frame-ancestors or X-Frame-Options) and a Referrer-Policy. A Content-Security-Policy is the strongest defense against cross-site scripting but needs some tuning.
Is a missing security header a vulnerability?
Not by itself. These headers are an extra layer that limits the damage of other bugs, such as injected script code. Without them, a site is easier to exploit when something goes wrong.
What does “Follow redirects” do?
When on, you see the headers of the final page after all redirects. When off, you see the first response – for example a 301 with its Location header.
Are HTTP header names case sensitive?
No. Under RFC 9110 header names are case-insensitive. The checker therefore shows them in lower case, the way HTTP/2 transmits them.
Sources and legal basis
- OWASP – HTTP Security Response Headers Cheat Sheet
- MDN – HTTP headers reference
- RFC 6797 – HTTP Strict Transport Security (HSTS)
- W3C – Content Security Policy Level 3
- hstspreload.org – HSTS preload requirements (max-age of at least one year)
- § 5.1 (field names are case-insensitive): RFC 9110 – HTTP Semantics
As of:
Related tools
- HTTP Status CodesLook up HTTP status codes: the meaning of 200, 301, 404, 500 and over 40 more codes explained, with search by code or keyword and a filter by class.
- Redirect Checker: Trace the Full Redirect ChainThis redirect checker traces every hop of a URL with its status code (301, 302, 307, 308), target and timing – and flags chains, loops and HTTPS mistakes.
- SEO Checker: Analyze Any Web Page for FreeAudit any URL: title, meta description, H1, canonical, hreflang, noindex, Open Graph, structured data and alt text – with an SEO score and clear fixes.
- DNS lookupLook up the DNS records of any domain: A, AAAA, MX, TXT, CNAME, NS, SOA, CAA, SRV and PTR – with TTL, DNSSEC status and explained error codes. Free.
- What is my IP address?Instantly shows your public IP address, detects IPv4 or IPv6 and explains the difference. Free, no sign-up – your IP address is never stored.
- ASCII table with decimal, hex, octal, binary and Unicode lookupComplete ASCII table (0–127) plus Latin-1 (128–255): decimal, hex, octal, binary, HTML entity, control codes. Look up any Unicode character, UTF-8 included.