Strict-Transport-Security
Tells browsers to use HTTPS for the site every time, so a visitor on hostile wifi cannot be dropped onto an unencrypted copy.
Free tool
Put in a web address and we will load the page once and tell you which of the six headers that protect its visitors are in place, what each one does, and how to fix the ones that are missing. Free, no sign up, and nothing is kept.
Check a site
What it checks
Security headers are instructions a website sends with every page, telling the browser what that page is allowed to do. Most take one line to add, and none of them cost anything.
Tells browsers to use HTTPS for the site every time, so a visitor on hostile wifi cannot be dropped onto an unencrypted copy.
Lists where scripts, styles and images may load from. The strongest defence against an injected script, and the hardest to get right.
Stops another site loading yours inside a frame and tricking people into clicking things they cannot see.
Stops browsers second guessing a file’s type and running something that was uploaded as a picture.
Limits how much of the page address is passed on when somebody clicks a link to another site.
Switches off browser features the site never uses, such as the camera, the microphone and location.
Questions
No. Headers protect the people visiting the site. They say nothing about the server behind it, the admin passwords, the plugins or the backups. What they do show, quickly and publicly, is whether anybody has looked, which is why they are worth checking.
Yes. The checker loads the page once, the same way a browser does, and reads the headers that come back. It does not scan, probe or try anything. If you are checking a supplier, it is a fair question to raise with them.
No. The address is used to fetch the page and build the result, and then it is dropped. Nothing is written to a database and there is no cookie. The privacy notice says the same.
Wherever the site is hosted. Web servers such as Apache, Nginx and IIS set them in their configuration, most content delivery networks, Cloudflare included, can add them without touching the site, and many hosting panels have a setting for it. If you do not know where your site is hosted, that is the first thing to find out, and we are happy to help you work it out. Whether headers matter for a small business site covers which to fix first.
Some sites put a firewall or bot filter in front of their pages that turns away automated requests, ours included. When that happens you see the headers on the error response, which can differ from the real pages. Loading the site in your own browser and opening the developer tools shows the real ones.
Next step
Headers are the part anybody can see from outside. Tell us what your website runs on and who looks after it, and we will tell you what is worth checking behind it.
Based in Cardiff, working across Wales and the West.