Free tool
Security headers checker
Check your website's HTTP security headers (CSP, HSTS, X-Frame-Options and more) and cookie flags, with a fix for each one missing.
What you get out of it
- See which browser protections your site is missing.
- Check that sign-in cookies cannot be stolen or misused.
- Get the exact header values to hand to your developer.
A one-off check is a snapshot. Add the domain to DomainGuard and it is watched: its uptime every five minutes on every plan, and on Starter and up every check here again each day, with an alert in the app when something important changes. What DomainGuard watches
What it checks
Security Headers
- HSTS checkHSTS tells browsers to only ever use HTTPS for your site, so a visitor on public Wi-Fi cannot be quietly downgraded.
- Content-Security-Policy checkCSP tells browsers which scripts your site is allowed to run, which stops most injected code from running on your visitors.
- X-Frame-Options checkStops other websites from loading yours inside an invisible frame to trick visitors into clicking things (clickjacking).
- X-Content-Type-Options checkStops browsers guessing a file's type, which blocks a class of attacks that disguise scripts as images or text.
- Referrer-Policy checkControls how much of your page addresses leak to other sites when visitors click a link.
- Permissions-Policy checkSwitches off browser features your site does not use (camera, microphone, location) so injected code cannot use them either.
- Cross-origin policy checkTwo headers that isolate your pages from other sites a visitor has open, closing off cross-site data leaks.
- X-XSS-Protection checkA retired header. Modern browsers ignore it, and the old filter it switched on could be abused, so it is best set to 0.
Page Security
- CSP script safety checkWhether your Content-Security-Policy still lets injected inline scripts and eval() run, which undoes most of what CSP is for.
- CSP violation reporting checkWhether your Content-Security-Policy tells you when it blocks something, so an attack or a broken page does not go unnoticed.
- Subresource integrity checkWhether scripts your site loads from other companies' servers carry a fingerprint, so a tampered copy is refused.
- Third-party script checkHow many other companies' scripts your homepage runs. Each one can see what your visitors see and type.
- Form security checkWhether the forms on your homepage send what people type over an encrypted connection.
- Cookie prefix checkWhether your site's important cookies use the __Host- and __Secure- name prefixes that make browsers enforce their protections.
Other free checkers
- Website & Domain ReportOne report on your email security, DNS, SSL, security headers, cookies, registration and reputation, with a link you can share with your IT provider.
- Email Security CheckerCheck SPF, DKIM, DMARC, MX, MTA-STS and TLS-RPT for your domain and find out whether your email can be spoofed or will land in spam.
- SPF CheckerCheck your domain's SPF record: whether it is valid, whether it stays under the 10-lookup limit, and how strictly it treats unlisted senders.
- DMARC CheckerCheck whether your domain has a DMARC record, what its policy is, and whether it protects your customers from email sent in your name.
- DKIM CheckerCheck whether your domain publishes DKIM keys for common mail providers, so receivers can verify your email is really from you.
- SSL CheckerCheck your website's SSL certificate: expiry date, trust chain, hostname coverage, TLS versions, HTTPS redirect and HSTS.
- DNS CheckerCheck your domain's nameservers, redundancy, MX records and CAA records, and find the DNS problems that take websites and email offline.
- Blacklist CheckerCheck whether the servers behind your domain are listed on the spam blocklists mail providers use to reject email.
- Domain Expiration CheckerCheck when your domain expires, who it is registered with, how old it is and who hosts the website, so a lapsed renewal never takes your site and email down.
