HTTP Header Checker
Analyze HTTP response headers for any URL. Check security headers, caching configuration, CORS settings, and server information.
Essential HTTP Security Headers
These headers protect your website against common web attacks. Our checker verifies all 7 critical security headers.
Content-Security-Policy
The most powerful security header. Controls which resources can load on your page, effectively preventing XSS and data injection attacks.
default-src 'self'; script-src 'self' 'unsafe-inline'Strict-Transport-Security
Forces HTTPS for all future visits. Once set, browsers will not connect via HTTP for the specified max-age duration.
max-age=31536000; includeSubDomains; preloadX-Frame-Options
Prevents your page from being embedded in iframes on other sites, blocking clickjacking attacks.
DENYPermissions-Policy
Restricts which browser APIs (camera, microphone, geolocation) the page can access.
camera=(), microphone=(), geolocation=()How to Add Security Headers
Nginx
add_header X-Frame-Options "DENY" always;
add_header X-Content-Type-Options "nosniff" always;
add_header Strict-Transport-Security "max-age=31536000; includeSubDomains" always;Apache (.htaccess)
Header always set X-Frame-Options "DENY"
Header always set X-Content-Type-Options "nosniff"
Header always set Strict-Transport-Security "max-age=31536000; includeSubDomains"Next.js (next.config.js)
async headers() {
return [{
source: '/(.*)',
headers: [
{ key: 'X-Frame-Options', value: 'DENY' },
{ key: 'X-Content-Type-Options', value: 'nosniff' },
],
}]
}Frequently Asked Questions
What are HTTP response headers?
What security headers should every website have?
What is Content-Security-Policy (CSP)?
What is HSTS and why is it important?
How do I check if my security headers are configured correctly?
What is the Permissions-Policy header?
Recommended: Sucuri
Website security platform: firewall, malware scanning, and DDoS protection.