URL-first security headers check

Review HTTP response headers before you publish

Enter a public URL to fetch response headers, or paste them from browser developer tools to review CSP, HSTS, clickjacking protection, and Cross-Origin headers. URL mode uses the bounded Web-Tool route.

Check a URL or response headers

Uses the bounded Web-Tool route without credentials, with a 2 MiB, 10-second, and redirect limit. Paste developer-tool headers for a manual check.

Up to 256 KiB. A status line is optional. Paste response headers only, not the response body or access logs.

What it checks

References

OWASP HTTP Headers Cheat Sheet / MDN Content-Security-Policy / MDN Strict-Transport-Security