What does Security Headers Checker validate?
It validates presence and values of key response security headers such as CSP, HSTS, X-Frame-Options, and Referrer-Policy.
Support
Everything you need to know about the Security Headers Checker tool, how it works, and how to interpret the results.
It validates presence and values of key response security headers such as CSP, HSTS, X-Frame-Options, and Referrer-Policy.
Yes. URLs with or without scheme are accepted and normalized automatically.
Missing or weak headers can expose applications to clickjacking, MIME sniffing, and data-leakage risk.
Yes. Checks are performed on the resolved final URL and include redirect-aware context.
Yes. Teams can enforce header baselines in CI and deployment smoke tests.
No. Checks are stateless and response-only.
Use Tool as one layer in a repeatable workflow: run diagnostics, log output, compare trend changes, and escalate anomalies before they affect crawl reliability or user experience.
Yes. Teams commonly combine results with DNS, SSL, canonical, and performance checks to build stronger release gates and faster incident triage.