⚙️

Security Headers Checker

Free security headers checker — test for CSP, HSTS, X-Frame-Options, and more. See which headers are missing and get implementation recommendations.

Frequently Asked Questions

What security headers should every site have?

Essential headers include Strict-Transport-Security (HSTS), Content-Security-Policy (CSP), X-Content-Type-Options, X-Frame-Options, and Referrer-Policy. These protect against common web attacks.

What is HSTS?

HTTP Strict Transport Security (HSTS) tells browsers to always use HTTPS for your domain. It prevents protocol downgrade attacks and cookie hijacking. Set max-age to at least 31536000 (1 year).

Do security headers affect SEO?

Indirectly. Security headers prevent attacks that could compromise your site, lead to malware warnings, or cause deindexing. HTTPS (enforced by HSTS) is a direct Google ranking signal.

Need Continuous Monitoring?

These tools provide one-time analysis. For continuous monitoring of your website's performance, uptime, and SEO health, try OpsKitty.