Free HTTP Header Checker
Inspect every HTTP response header, get a security grade (A+ → F), and see exactly which security headers are missing or misconfigured.
How it works
Paste a URL
We follow redirects and fetch the final response, capturing every header.
Score security headers
HSTS, CSP, X-Content-Type-Options, X-Frame-Options, Referrer-Policy, Permissions-Policy — each rated and explained.
Read the grade
A simple A+ → F grade based on what's present, plus the full header dump for debugging.
Frequently asked questions
What grade should I aim for?+
A or A+. Most production SaaS sites get there by setting HSTS, CSP, X-Content-Type-Options, Referrer-Policy, and a Permissions-Policy. Frame-ancestors in CSP can replace X-Frame-Options.
Why does my page have HSTS but get a warning?+
max-age below 6 months (15552000 seconds) downgrades the rating. Bump to a year (31536000) for production.
What about caching headers?+
We show every response header in the bottom section — Cache-Control, ETag, Age, Vary, etc. The security grade focuses specifically on the headers that affect attack surface.
Does this follow redirects?+
Yes. We follow up to the default redirect limit and grade the headers on the FINAL response (the one the browser actually renders).
Building a SaaS that needs custom domains?
Domainee is the API for adding customer custom domains to your product. One CNAME, automatic TLS, no DevOps to staff.
50 custom domains and 100 GB bandwidth free, forever.
More free tools
SSL
Free SSL Certificate Checker
View issuer, validity, expiration countdown, and certificate chain for any domain.
DNS
Free DNS Record Lookup
Check A, AAAA, CNAME, MX, TXT, NS, and SOA records for any domain instantly.
Domain
Free WHOIS Lookup
View registrar, creation and expiry dates, name servers, and registration data for any domain.
DNS
Free CNAME Lookup & Generator
Validate CNAME records and get provider-specific setup instructions for custom domains.
DNS
Free DNS Propagation Checker
Query DNS servers across multiple global locations to verify your DNS changes are live.
Other
Free Custom Domain Cost Calculator
Compare building in-house vs. using a managed service for custom domains on your SaaS.