Security headers checker
Type a page address. We request it once, the way a browser does, and read the response headers and the cookies it sets before you click anything.
Free, no sign-up. We read public pages and DNS only, and keep nothing.
What it checks
- Strict-Transport-Security (HSTS)
- Content-Security-Policy
- X-Frame-Options or CSP frame-ancestors
- Referrer-Policy, Permissions-Policy, X-Content-Type-Options
- Cookie flags: Secure, SameSite, total size
- Compression of the HTML
Why it matters
These headers are the browser's instructions for keeping visitors safe: stay on HTTPS, run only your scripts, do not let other sites frame you. Each one is a line of server config.
Headers can differ between pages and between a signed-in and a signed-out visit. This reads the address you type, signed out.
This is one check. The free audit runs all of them.
Security headers, DMARC and SPF, search tags, structured data, sitemap, AI crawler access, accessibility and real-user speed, on up to 20 pages in a real browser, with a fix prompt for each finding.