HTTP Header Checker with Security Grade

This HTTP header checker shows every response header a server sends for an address – from Content-Type and Cache-Control to Set-Cookie – and grades the security headers against OWASP recommendations from A to F. Each gap comes with the header value to add.

Source: OWASP – HTTP Security Response Headers Cheat Sheet. Updated: .

Off: show the headers of the first response (e.g. the 301) instead of the final page.
My Toolbox

When you click, your browser sends the URL you entered to our server (a Cloudflare Worker). It fetches the page as “ToolboxDayBot”, respects its robots.txt and returns only the analysis. URLs and IP addresses are not stored; for the limit of 30 checks per hour the server keeps a one-way hash of your IP in memory for at most one hour.

Result

Security grade
–
Response
–
Security headers
Tips
All headers
Redirects

How it is calculated

Security headers at a glance

HeaderProtects againstRecommended value (OWASP)
Strict-Transport-SecurityEavesdropping, downgrade to http://max-age=63072000; includeSubDomains
Content-Security-PolicyCross-site scripting, foreign scriptssite-specific, e.g. default-src 'self'
X-Content-Type-OptionsMIME sniffingnosniff
X-Frame-Options or frame-ancestorsClickjackingDENY or frame-ancestors 'none'
Referrer-PolicyLeaking full URLsstrict-origin-when-cross-origin
Permissions-PolicyAbuse of camera, microphone, locationgeolocation=(), camera=(), microphone=()
Cross-Origin-Opener-PolicyAttacks via opened windowssame-origin

The checker also flags Server or X-Powered-By headers that reveal version numbers, and cookies set without Secure, HttpOnly or SameSite. The deprecated X-XSS-Protection header is listed as info only – OWASP advises setting it to 0 or leaving it out.

How the grade is calculated

HSTS and Content-Security-Policy are worth 20 points each; X-Content-Type-Options, clickjacking protection, Referrer-Policy, version disclosure and cookies 10 each; Permissions-Policy and Cross-Origin-Opener-Policy 5 each. A pass earns full points, “review” half, missing nothing. The percentage becomes a grade: A from 90 %, B from 75 %, C from 60 %, D from 45 %, E from 30 %, F below. The weighting is our own judgment based on the OWASP HTTP Headers Cheat Sheet.

Setting headers yourself

Roll out a Content-Security-Policy as Content-Security-Policy-Report-Only first and enforce it once nothing legitimate would be blocked. Only enable HSTS when the site – and with includeSubDomains every subdomain – runs on HTTPS for good.

Limitations

You see the headers returned to our request from a Cloudflare data center. Some servers answer browsers, other countries or logged-in users with different headers. Cookie values are never passed on: only names and attributes are shown.

Frequently asked questions

How do I check the HTTP headers of a website?

Enter the address and click “Check headers” – the “All headers” table lists each header with its value. In your browser you can also open the developer tools (F12), go to the Network tab, click the request and choose “Headers”.

Which security headers should every website have?

At a minimum Strict-Transport-Security, X-Content-Type-Options: nosniff, clickjacking protection (frame-ancestors or X-Frame-Options) and a Referrer-Policy. A Content-Security-Policy is the strongest defense against cross-site scripting but needs some tuning.

Is a missing security header a vulnerability?

Not by itself. These headers are an extra layer that limits the damage of other bugs, such as injected script code. Without them, a site is easier to exploit when something goes wrong.

What does “Follow redirects” do?

When on, you see the headers of the final page after all redirects. When off, you see the first response – for example a 301 with its Location header.

Are HTTP header names case sensitive?

No. Under RFC 9110 header names are case-insensitive. The checker therefore shows them in lower case, the way HTTP/2 transmits them.

Sources and legal basis

As of:

Related tools