Skip to content

HTTP security

HTTP security headers checker

See which security headers a site's home page sends over HTTPS: the instructions that keep a browser on HTTPS, limit where scripts may come from, stop other sites framing the page and switch off features it does not use. Each header is reported as passed or needing attention, with no grade.

Checked from Ironfang Security's scanner address with the same low-impact limits as a scan. Nothing you enter is kept.

What this checks

What the result means

Security headers are instructions a server attaches to its responses, and browsers act on them: they switch to HTTPS before connecting, refuse scripts from sources a policy does not allow, and decline to show a page inside another site. A missing header is not a vulnerability in itself. It is a defence the browser would apply and currently does not.

The result counts each check on each host as passed or needing attention. There is no grade or score: the seven checks do not carry equal weight, and a letter for headers says nothing about the rest of the site. Every finding this page can raise is hardening, each with the severity shown beside it.

Where the domain and its www. name are served by different systems, their headers often differ, so each host is listed on its own with the full set of headers it returned.

How to fix common issues

HSTS is not enabled

Add Strict-Transport-Security: max-age=31536000; includeSubDomains to HTTPS responses once every subdomain serves HTTPS. Start with a short max-age if you are unsure, then raise it.

More in the HTTP Strict Transport Security check reference

HSTS max-age is short

Raise max-age to at least one year (31536000 seconds).

More in the HTTP Strict Transport Security check reference

No Content Security Policy

Start with a report-only policy (Content-Security-Policy-Report-Only) to see what your pages load, then enforce a policy such as default-src 'self' plus the sources you need.

More in the Content Security Policy check reference

Content Security Policy allows inline scripts

Move inline scripts into files, or use nonces or hashes, then remove 'unsafe-inline' from script-src.

More in the Content Security Policy check reference

X-Content-Type-Options is not set

Add X-Content-Type-Options: nosniff to all responses.

More in the X-Content-Type-Options check reference

Pages can be framed by other sites

Add Content-Security-Policy: frame-ancestors 'self' (or X-Frame-Options: SAMEORIGIN for older browsers). If other sites legitimately embed your pages, list them in frame-ancestors.

More in the Clickjacking protection check reference

No Referrer-Policy

Add Referrer-Policy: strict-origin-when-cross-origin.

More in the Referrer-Policy check reference

No Permissions-Policy

Add a policy that disables features you do not use, for example Permissions-Policy: camera=(), microphone=(), geolocation=().

More in the Permissions-Policy check reference

Software version disclosed in headers

Turn off version banners: server_tokens off; in nginx, ServerTokens Prod and ServerSignature Off in Apache, expose_php = Off in php.ini, and remove X-Powered-By where your framework adds it.

More in the Server information disclosure check reference

Cyber Essentials and ISO 27001

Neither Cyber Essentials nor ISO 27001 names HTTP security headers. A consistent set of them is technical evidence of how a web server is configured, which is what Cyber Essentials' secure configuration theme and ISO/IEC 27001:2022 Annex A 8.9 (configuration management) are concerned with.

The organisation still has to set the baseline: which headers its sites must send, who owns that standard, how changes to web server, CDN and framework settings are approved, and how a release is checked against it. A header check shows the current setting on one page, not the process that keeps it there.

Scope and limitations

Related guides

Questions

Which security headers should a website send?
Most sites should send Strict-Transport-Security, Content-Security-Policy, X-Content-Type-Options: nosniff, a framing control (CSP frame-ancestors or X-Frame-Options), Referrer-Policy and Permissions-Policy. The right values depend on what the site loads and who embeds it.
Do security headers need to be on every page?
Mostly, yes. A browser applies HSTS to the whole host once it has seen it, but a Content Security Policy, a framing control and nosniff apply only to the response they arrive on. Set them once at the web server, CDN or framework rather than page by page.
Why does this checker not give a grade?
Ironfang's scanner has no score to give. Each check passes or raises a finding with its own severity, and the page shows those counts. A letter grade would add the headers up as if they weighed the same, and they do not.

Related security tools