HTTP Header Check

View the HTTP response headers for any URL with a security header scorecard (HSTS, CSP, X-Frame-Options and more).

Join a Session

Free tools from Total Group, IT support, cyber security and compliance for regulated businesses. Lookups run on our own servers; nothing you enter is stored or shared. Need help fixing what a check found? Talk to us.

Frequently asked questions

Which HTTP security headers should a website have?

At a minimum: Strict-Transport-Security (HSTS), Content-Security-Policy, X-Content-Type-Options, X-Frame-Options or frame-ancestors, and Referrer-Policy. They protect visitors against downgrade, clickjacking and content-injection attacks.