Website diagnostics

HTTP Security Headers Checker

Observe selected browser security and cross-origin response headers without reducing a nuanced configuration to a grade.

Inspect security headers

Different headers solve different problems

HSTS asks browsers to use HTTPS for future visits. CSP limits permitted resource sources. X-Content-Type-Options controls MIME sniffing; Referrer-Policy limits referrer disclosure; Permissions-Policy controls selected browser features; and COOP, COEP and CORP shape cross-origin isolation. Compare general response metadata in the Server Headers Checker, certificate identity in the SSL Checker, and your own request in the HTTP Headers Checker.