Web Security Guide

How to Check Website Security Headers

HTTP security headers allow a website to instruct browsers how to handle transport security, content execution, framing, MIME types, referrer information, and access to browser capabilities.

Open HTTP Header Analyzer →

What are HTTP security headers?

HTTP response headers can provide browsers with additional security instructions that are not expressed directly by page content.

A security-header review helps identify whether important browser protections are configured on a website.

How to check website security headers

  1. 1. Enter the public website URL.
  2. 2. Open the HTTP Header Analyzer.
  3. 3. Analyze the response.
  4. 4. Review present, missing, and potentially unsafe headers.

For a broader website assessment that also reviews TLS, certificates, redirects, and cookies, use the Website Security Scanner.

Important website security headers

Content-Security-Policy

CSP controls which sources can provide scripts, styles, images, frames, and other resources. A well-designed policy can significantly reduce the impact of content injection attacks.

Strict-Transport-Security

HSTS tells compatible browsers to use HTTPS for the site for a specified period.

X-Content-Type-Options

The nosniff value prevents browsers from attempting to reinterpret some resources as a different MIME type.

Referrer-Policy

Referrer-Policy controls how much referring URL information a browser sends when navigating or requesting resources.

Permissions-Policy

Permissions-Policy controls access to browser capabilities such as camera, microphone, geolocation, and other features.

X-Frame-Options and CSP frame-ancestors

These controls can restrict whether other sites may embed a page in a frame, reducing clickjacking exposure.

How to inspect headers with curl

You can also view HTTP response headers from the terminal:

curl -I https://example.com

Does every website need the same security headers?

No. Appropriate security headers depend on the application, architecture, integrations, browser requirements, and risk profile.

For example, an overly restrictive Content Security Policy can break legitimate scripts or integrations if it is enabled without testing.

Security headers are not a vulnerability scan

Header analysis reviews browser-facing configuration. It does not prove that an application is free from vulnerabilities.

Application security testing may also require code review, authenticated testing, dependency analysis, business-logic testing, and other assessment techniques.

Related tools

Check your website security headers

Inspect the headers returned by a public website and review common browser-facing security controls.

Open HTTP Header Analyzer →