What are HTTP security headers?
HTTP response headers can provide browsers with additional security instructions that are not expressed directly by page content.
A security-header review helps identify whether important browser protections are configured on a website.
How to check website security headers
- 1. Enter the public website URL.
- 2. Open the HTTP Header Analyzer.
- 3. Analyze the response.
- 4. Review present, missing, and potentially unsafe headers.
For a broader website assessment that also reviews TLS, certificates, redirects, and cookies, use the Website Security Scanner.
Important website security headers
Content-Security-Policy
CSP controls which sources can provide scripts, styles, images, frames, and other resources. A well-designed policy can significantly reduce the impact of content injection attacks.
Strict-Transport-Security
HSTS tells compatible browsers to use HTTPS for the site for a specified period.
X-Content-Type-Options
The nosniff value prevents browsers from attempting to reinterpret some resources as a different MIME type.
Referrer-Policy
Referrer-Policy controls how much referring URL information a browser sends when navigating or requesting resources.
Permissions-Policy
Permissions-Policy controls access to browser capabilities such as camera, microphone, geolocation, and other features.
X-Frame-Options and CSP frame-ancestors
These controls can restrict whether other sites may embed a page in a frame, reducing clickjacking exposure.
How to inspect headers with curl
You can also view HTTP response headers from the terminal:
curl -I https://example.comDoes every website need the same security headers?
No. Appropriate security headers depend on the application, architecture, integrations, browser requirements, and risk profile.
For example, an overly restrictive Content Security Policy can break legitimate scripts or integrations if it is enabled without testing.
Security headers are not a vulnerability scan
Header analysis reviews browser-facing configuration. It does not prove that an application is free from vulnerabilities.
Application security testing may also require code review, authenticated testing, dependency analysis, business-logic testing, and other assessment techniques.
Related tools
HTTP Header Analyzer
Inspect response headers and common browser security controls.
Open tool →Website Security Scanner
Review HTTPS, TLS, certificates, redirects, headers, and cookies.
Open tool →CSP Builder
Create a Content Security Policy for your website.
Open tool →SSL/TLS Checker
Inspect TLS protocols, certificate chains, and security findings.
Open tool →Check your website security headers
Inspect the headers returned by a public website and review common browser-facing security controls.
Open HTTP Header Analyzer →