Skip to content
SEO SMO HUB
Get Free Audit

Address: Jaipur, Rajasthan, India

[email protected]

Security Headers Checker

This free security headers checker requests your URL and grades six response headers out of 100 with a letter from A to F: Strict-Transport-Security, Content-Security-Policy, X-Content-Type-Options, X-Frame-Options, Referrer-Policy and Permissions-Policy. Each gap comes with a ready-to-paste line for Nginx and Apache, so you can fix it in minutes.

Security Headers Checker

Technical SEO

Free

Headers can differ by page, so test your home page and a key inner page.

Free, no signup. We cache each result on our server for a short time so a repeat check is instant; nothing is linked to you.

About this tool

Security headers are short instructions your server sends with every page that tell the browser how strictly to behave. They can force HTTPS, stop your pages being framed by other sites, block the browser from guessing file types, limit which scripts may run, and decide how much of your address is shared when a visitor clicks a link. Most cost one line of server configuration.

The checker fetches the page and scores six headers: Strict-Transport-Security (20 points), Content-Security-Policy (25), X-Content-Type-Options (15), clickjacking protection through X-Frame-Options or frame-ancestors (15), Referrer-Policy (10) and Permissions-Policy (15). A weak value earns half the points. The total gives the grade: A from 90, B from 75, C from 60, D from 40, E from 20 and F below that.

The grade measures which headers are present and not obviously weak, not whether your site is secure. A site can score A and still have vulnerable code, and a Content-Security-Policy is checked for presence and obvious weaknesses, not tested against your scripts. Add headers one at a time and test the site, especially the Content-Security-Policy, which can block scripts you rely on.

Frequently asked questions

What is a good security headers grade?

A or B is a strong result for most sites. A Content-Security-Policy is the hardest header to add safely, so many good sites sit at B or C until they build a policy. Fix the quick ones first: HSTS, X-Content-Type-Options, a framing rule, Referrer-Policy and Permissions-Policy.

Will security headers improve my rankings?

Google does not rank sites by their headers. They protect visitors and your brand, and HSTS can save a redirect. They also build trust with security-minded clients and partners. Treat them as site hygiene that belongs next to HTTPS, not as an SEO tactic.

Can a Content-Security-Policy break my site?

Yes. A strict policy blocks any script, style or frame it does not allow, including analytics, chat widgets and ad code, so a rushed policy can break features visitors rely on. Start with Content-Security-Policy-Report-Only, review what would be blocked, adjust the policy, then switch to enforcing mode.

Where do I add these headers?

In the web server configuration (Nginx add_header, Apache Header set), in a CDN rule such as Cloudflare Transform Rules, or in your application code. On shared hosting you can often add them in the .htaccess file. The fix snippets below show both Nginx and Apache forms.