Security Headers Checker

Grade a website's HTTP security headers, such as HSTS, CSP and X-Frame-Options, and see how to fix them.


Security Headers Checker

HTTP security headers are instructions your server sends with every page that switch on browser protections: always use HTTPS, only run scripts from trusted places, do not show this page inside another site's frame. They are free to add and stop whole classes of attacks. This checker reads a page's headers, grades them from A to F and shows an example for each missing one.

How to use Security Headers Checker

  1. Enter the address of a page, usually your homepage.
  2. Click Check headers.
  3. Work through the missing and weak headers. Each one has a short explanation and an example value to start from.

When it comes in handy

  • Hardening a website after launch or a security review.
  • Checking that headers set in your server, CDN or plugin are actually sent.
  • Comparing your setup with other sites in your industry.

Frequently asked questions

Where do I add these headers?
In your web server configuration (.htaccess on Apache or LiteSpeed, the server block on Nginx), in your CDN's settings, or with a security plugin in your CMS.
Can adding headers break my site?
Content-Security-Policy can, if it blocks scripts your site needs. Start with Content-Security-Policy-Report-Only, watch the reports, then enforce it. The other headers rarely cause problems.
Do security headers help SEO?
Not directly, but HTTPS is a ranking signal and HSTS keeps visitors on HTTPS. A hacked site, which these headers help prevent, can lose its rankings entirely.

Choose which cookies SEOpeck may use. You can change this at any time from "Cookie settings" at the bottom of every page.