Free tool · no sign-up
Free security headers checker
Security headers are small settings that tell browsers to block common attacks such as clickjacking and malicious scripts. See which ones your site sends, and how its cookies are protected.
Check everything at once
This tool looks at one area. The full website security scan also checks SSL, email spoofing protection, exposed files and outdated software, and gives you a score and a fix plan.
Free Security Watch
Keep an eye on your website, free
- A short re-scan summary by email once a month: your score, what changed and the top issues.
- A reminder 21 and 7 days before your SSL certificate expires.
- A reminder 30 days before your domain registration expires, when the registry publishes the date.
Up to 3 websites per email address. Unsubscribe with one click from any email. Need weekly scans, every finding and instant alerts? See Monitoring (C$399 / year).
Questions about the Security Headers Checker
Which security headers matter most?
Strict-Transport-Security (forces HTTPS), Content-Security-Policy (limits where scripts can load from), X-Frame-Options or CSP frame-ancestors (stops clickjacking) and X-Content-Type-Options. Referrer-Policy and Permissions-Policy add privacy and limit browser features.
Can adding headers break my website?
Most cannot. Content-Security-Policy can block scripts your site relies on, so start it in report-only mode or test it on a staging copy first. HSTS should be added only once HTTPS works everywhere on the domain.
Where do I add these headers?
In your web server configuration (.htaccess on Apache/cPanel, the server block on Nginx), in a CDN such as Cloudflare, or with a security plugin on WordPress. The full scan report includes copy-paste snippets for each.
Why are cookie flags included?
Cookies without the Secure, HttpOnly and SameSite flags are easier to steal or misuse. The checker looks at the cookies your home page sets.
Checking the security of
your website
- SSL certificateIs HTTPS valid, current and correctly set up?
- Security headersBrowser protections against clickjacking and script injection
- DNS and email securitySPF, DMARC and DKIM records that stop fake emails
- TechnologyVisible software and versions attackers look for
- ExposureBackup files, config files and admin pages left public
This usually takes 10 to 30 seconds. Please keep this page open.