HTTP security
HTTP security headers checker
See which security headers a site's home page sends over HTTPS: the instructions that keep a browser on HTTPS, limit where scripts may come from, stop other sites framing the page and switch off features it does not use. Each header is reported as passed or needing attention, with no grade.
What this checks
- The home page over HTTPS for the domain and its
www.name, or only the name entered if it is a subdomain, following up to three redirects that stay on those names. Headers are judged on the final response. - Transport and scripts:
Strict-Transport-Securitywith amax-ageof at least 180 days, and an enforcedContent-Security-Policythat does not let inline scripts run. - Framing: a CSP
frame-ancestorsdirective, orX-Frame-Optionsset toDENYorSAMEORIGIN. - Browser behaviour:
X-Content-Type-Options: nosniff, aReferrer-Policy, and aPermissions-Policy(the olderFeature-Policyalso counts). - Disclosure: a version number in
Server,X-Powered-By,X-AspNet-Version,X-AspNetMvc-VersionorX-Generatoron any response the check received.
What the result means
Security headers are instructions a server attaches to its responses, and browsers act on them: they switch to HTTPS before connecting, refuse scripts from sources a policy does not allow, and decline to show a page inside another site. A missing header is not a vulnerability in itself. It is a defence the browser would apply and currently does not.
The result counts each check on each host as passed or needing attention. There is no grade or score: the seven checks do not carry equal weight, and a letter for headers says nothing about the rest of the site. Every finding this page can raise is hardening, each with the severity shown beside it.
Where the domain and its www. name are served by different systems, their headers often differ, so each host is listed on its own with the full set of headers it returned.
How to fix common issues
HSTS is not enabled
Add Strict-Transport-Security: max-age=31536000; includeSubDomains to HTTPS responses once every subdomain serves HTTPS. Start with a short max-age if you are unsure, then raise it.
HSTS max-age is short
Raise max-age to at least one year (31536000 seconds).
No Content Security Policy
Start with a report-only policy (Content-Security-Policy-Report-Only) to see what your pages load, then enforce a policy such as default-src 'self' plus the sources you need.
Content Security Policy allows inline scripts
Move inline scripts into files, or use nonces or hashes, then remove 'unsafe-inline' from script-src.
X-Content-Type-Options is not set
Add X-Content-Type-Options: nosniff to all responses.
Pages can be framed by other sites
Add Content-Security-Policy: frame-ancestors 'self' (or X-Frame-Options: SAMEORIGIN for older browsers). If other sites legitimately embed your pages, list them in frame-ancestors.
No Referrer-Policy
Add Referrer-Policy: strict-origin-when-cross-origin.
No Permissions-Policy
Add a policy that disables features you do not use, for example Permissions-Policy: camera=(), microphone=(), geolocation=().
Software version disclosed in headers
Turn off version banners: server_tokens off; in nginx, ServerTokens Prod and ServerSignature Off in Apache, expose_php = Off in php.ini, and remove X-Powered-By where your framework adds it.
Cyber Essentials and ISO 27001
Neither Cyber Essentials nor ISO 27001 names HTTP security headers. A consistent set of them is technical evidence of how a web server is configured, which is what Cyber Essentials' secure configuration theme and ISO/IEC 27001:2022 Annex A 8.9 (configuration management) are concerned with.
The organisation still has to set the baseline: which headers its sites must send, who owns that standard, how changes to web server, CDN and framework settings are approved, and how a release is checked against it. A header check shows the current setting on one page, not the process that keeps it there.
Scope and limitations
- It reads the home page only. Other paths, an application behind a login and API responses can send different headers, and often do.
- Headers are checked for presence and a few key values, not audited in depth. A
Content-Security-Policypasses here as long as it is enforced and blocks inline scripts, however many sources it allows. - Cookies, the HTTP to HTTPS redirect and security.txt are not part of this result. The cookie security, HSTS and security.txt checkers show them.
- It is an automated, low-impact external check: a few ordinary requests from one address, no login and no attack traffic. It is not a penetration test, and a clean result does not mean the site is secure.
Related guides
Questions
- Which security headers should a website send?
- Most sites should send Strict-Transport-Security, Content-Security-Policy, X-Content-Type-Options: nosniff, a framing control (CSP frame-ancestors or X-Frame-Options), Referrer-Policy and Permissions-Policy. The right values depend on what the site loads and who embeds it.
- Do security headers need to be on every page?
- Mostly, yes. A browser applies HSTS to the whole host once it has seen it, but a Content Security Policy, a framing control and nosniff apply only to the response they arrive on. Set them once at the web server, CDN or framework rather than page by page.
- Why does this checker not give a grade?
- Ironfang's scanner has no score to give. Each check passes or raises a finding with its own severity, and the page shows those counts. A letter grade would add the headers up as if they weighed the same, and they do not.
Related security tools
- Content Security Policy checker - Read a site's Content-Security-Policy directive by directive and spot unsafe inline scripts.
- HSTS checker - Check Strict-Transport-Security: max-age, includeSubDomains, preload and the HTTP redirect.
- SSL/TLS checker - Check a site's HTTPS, certificate, expiry, TLS versions and weak cipher suites.
- Website security checker - Check a domain's DNS, email authentication, TLS, security headers and public technology in one pass.

