HTTP Header Security Checker

Check the security measures in HTTP response headers

Features

Major security headers

List the configuration status of 10 headers such as HSTS and CSP

Visualize safety with a score

Show the proportion of configured items, excluding deprecated ones, as a score and badge

Highlight unset headers

Check missing headers and the role of each item on the spot

Display all response headers

Review all headers in a list, including those outside the security scope

How to use

1

Enter a URL

Enter the URL of the site you want to examine in the input field; you can also pick from samples

2

Run the check

Press the run button and the server retrieves and analyzes the headers

3

Check the score and details

Check the overall safety from the score badge and each header's configuration status in the table

Use cases

Safety inspection of your own site

Periodically check whether the header measures of your published site are sufficient

Finding gaps in measures

Identify unset headers and pinpoint the items you should add

Investigating other sites' settings

Check the header configuration policy of sites you want to reference

Final check before release

Inspect for missing security header settings before release

Basic Knowledge

What are Security Headers?

Security headers are a collection of headers that servers include in responses to communicate security instructions to browsers. By simply configuring them, you can strengthen defenses against eavesdropping, spoofing, and unauthorized embedding attacks.

Common Security Headers

  • HSTS:HSTS (Strict-Transport-Security) is a header that instructs browsers to always use HTTPS for subsequent access.
  • CSP:CSP (Content-Security-Policy) is a header that restricts the sources of scripts and images allowed to load, preventing the execution of malicious code.
  • X-Frame-Options:X-Frame-Options is a header that restricts embedding a page in iframes on other sites, preventing clickjacking attacks.

Safety and Privacy

Server-side processing

Input is processed on the server; only information necessary for the inquiry is sent.

Temporary processing only

For analyzing headers, temporary processing occurs on the server, then data is discarded after results are returned.

Communications encrypted with HTTPS

All sent and received data is encrypted by TLS and cannot be read by third parties.

No transmission to third parties

Input content is not sent to external services such as ad networks or trackers.

Sent only to the target URL

Executes only a HEAD request to the entered URL to retrieve headers

Follow RAKKOTOOLS on Google Search

175 useful tools become easier to find from Google Search and AI Search!

  • Found in search
  • Also shown in AI Search
  • Discover new tools
Related Tools