Security Headers Check

Paste the response headers of a page — curl -sI https://your-site.example/ in a terminal, or the block from the browser Network panel — and get an A+ to F grade on the OWASP Secure Headers checklist: Strict-Transport-Security, Content-Security-Policy, X-Content-Type-Options, framing protection, Referrer-Policy, Permissions-Policy, the cross-origin isolation trio, version leaks, deprecated headers and cookie flags — each finding paired with the exact nginx, Apache and Express lines that fix it. Everything runs in your browser; the page never contacts your site.
The status line is optional. Multiple Set-Cookie lines are all checked. To have a policy to grade in the first place, build one on the CSP generator; to take a header block apart line by line, use the HTTP header parser.
No grade yet. Paste response headers and press Check headers, or load a sample.
Fix lines for every finding appear here after a check.
Scope of this checker versus the SSL Security Check. This page grades the security response headers (the OWASP list above). The SSL Security Check grades your HTTPS setup: certificate chain, protocol versions, cipher strength and mixed content. HSTS and cookie flags appear on both pages because both lists include them, but with different lenses - run both checks for the full picture.
Self-test
Re-runs the grader against fixed header blocks: the good sample at A+, the bad sample at F with every deduction fired, each rule in isolation (the arithmetic of the score), the version-leak cap, cookie advisories, CSP quality notes, frame-ancestors counting as framing protection, grade thresholds on both sides of every boundary, the fix snippets, and the negative paths. Nothing is sent anywhere.
What are security headers?
In one sentence: security headers are response headers that instruct the browser to enforce a protection it could not figure out on its own — never load scripts from unknown origins, never speak plain HTTP to this host again, never frame this page — and they cost one configuration line each.
The headers this page grades
HeaderProtects againstOWASP recommended value
Strict-Transport-Securityprotocol downgrade and cookie theft on the first plain-HTTP requestmax-age=63072000; includeSubDomains
Content-Security-Policycross-site scripting, malicious embeds, mixed contentdefault-src 'self'; form-action 'self'; base-uri 'self'; object-src 'none'; frame-ancestors 'none'; upgrade-insecure-requests
X-Content-Type-OptionsMIME confusion (a script served as an image)nosniff
X-Frame-Options / CSP frame-ancestorsclickjacking (your page framed by an attacker)deny / 'none'
Referrer-Policyleaking URLs (with tokens) to third-party sitesno-referrer
Permissions-Policypages and embeds silently using camera, mic, geolocationall features disabled
Cross-Origin-Opener-Policyother windows reaching into your browsing contextsame-origin
Cross-Origin-Embedder-Policyloading resources that did not opt in (enables process isolation)require-corp
Cross-Origin-Resource-Policyyour resources embedded by other sitessame-origin
How the grade is computed

Start at 100 and subtract: −25 missing CSP, −20 missing HSTS, −10 each for missing X-Content-Type-Options, Referrer-Policy or any framing protection, −5 each for the cross-origin trio and Permissions-Policy, −5 for version leaks in Server/X-Powered-By (capped), and −5 for a non-zero X-XSS-Protection. Letter grades: 100 = A+, 90+ = A, 80+ = B, 70+ = C, 60+ = D, below = F. Advisory notes (cookie flags, cache control, CSP quality) do not subtract.

Common mistakes
  • Setting headers on the wrong responses. Add them on every response, including error pages and redirects - that is what the always in add_header ... always; (nginx) and Header always set (Apache) is for.
  • Testing only the homepage. Proxies, caches and legacy apps often strip or override headers on some paths only. Check the pages that matter: login, checkout, API endpoints.
  • Keeping X-XSS-Protection. The auditor it drove caused vulnerabilities of its own; browsers removed it. A non-zero value now costs score on purpose - remove it and let CSP do the job.
  • Believing X-Frame-Options is current. It cannot allow specific origins and is not in the CSP standard; frame-ancestors is the modern replacement. Keeping both during the transition is fine - this page accepts either.
  • Shipping version banners. Server: Apache/2.4.58 (Unix) narrows an attacker's search for known bugs at zero benefit. Strip the version; keep the line count down.
FAQ

Why is COOP/COEP/CORP only worth 5 points each? The trio is the newest layer, mainly needed where you want process isolation (SharedArrayBuffer, Spectre-hardening). A site without them still has its core protections; with them, some cross-origin embeds need adjustments - which is why they weigh less than CSP or HSTS.

Does a high grade mean the site is secure? No - it means the response headers are set. Security headers are one layer: TLS configuration, session handling, input validation and patching still decide whether the site is actually secure. Run the SSL Security Check for the TLS layer.

Why is my Permissions-Policy value so long? The OWASP baseline switches off every feature explicitly, so a browser adding new features does not silently re-enable them. A shorter value like camera=(), microphone=(), geolocation=() is a start - just know what it leaves on.

Can I check headers of any site from here? This page never makes network requests - it grades exactly the text you paste, so it works behind firewalls and on internal hosts, and nothing you inspect leaves your machine. Fetching the headers is one curl -sI in your terminal.

What about Clear-Site-Data and X-Permitted-Cross-Domain-Policies? Useful in narrow scenarios (logout responses; legacy PDF/Flash viewers). They are advisory here, not scored - sending Clear-Site-Data on every response would wipe your users' storage every page load.