SSL & Web Headers100% In-BrowserHeader Audit

Security Headers Inspector

Scan web servers for critical headers: CSP, HSTS, X-Frame-Options, X-Content-Type-Options, and Referrer-Policy.

Real-time processing·No server uploads·Zero telemetry
security-headers-inspector
LIVE
Paste HTTP Response Headers
Tip: Use curl -I https://example.com to fetch headers
A100
Security Score
A+ grade · 6 of 6 security headers present
Content-Security-Policy
default-src 'self'; script-src 'self'; style-src 'self' 'unsafe-inline'; object-src 'none';
Strict-Transport-Security
max-age=63072000; includeSubDomains; preload
X-Frame-Options
DENY
X-Content-Type-Options
nosniff
Referrer-Policy
strict-origin-when-cross-origin
Permissions-Policy
geolocation=(), camera=(), microphone=()

How to Use Security Headers Inspector

01

Enter website URL to scan.

02

Review the security score card and missing headers.

03

Copy recommended header configurations for Nginx, Apache, or Cloudflare.

Privacy Guarantee

Security Headers Inspector runs 100% client-side in your web browser. Your data, passwords, keys, and files are processed using the Web Crypto API and never transmitted to any server. Zero telemetry, zero storage, zero cloud processing.

Frequently Asked Questions

What is an A+ security header score?

An A+ requires a strict CSP, HSTS with preload, X-Content-Type-Options, and Referrer-Policy.

Discover More

Related Security Tools

View All Security Tools