Skip to main content
ssl

Security Headers

Security Headers helps you check security-related http headers, for certificate inspection, HTTPS validation, and TLS troubleshooting.

Enter the full URL including https://

Security HeadersHTTP headers harden the page behind a security shield.

Advertisement · Anuncio

Advertisement · Anuncio

Technical Analysis & Guide

What It Does

Security Headers Check analyzes HTTP response headers to identify missing or misconfigured security headers like HSTS, CSP, X-Frame-Options, and others that protect against common web attacks.

Illustration of ssl concept

Why It Matters

  • →XSS Protection: Content-Security-Policy prevents cross-site scripting attacks
  • →Clickjacking: X-Frame-Options stops your site being embedded in iframes
  • →HTTPS Enforcement: HSTS ensures users always use secure connections
  • →Compliance: Many security standards require proper header configuration

How to Read Results

  • Present: Header is configured (check the specific policy)
  • Missing: Header not found - potential security risk
  • Grade: Overall security rating (A+ is best)
  • Recommendations: Specific improvements for each missing header

Technical Background

Security headers are instructions a server attaches to an HTTP response telling the browser which protections to enforce for that page. They cost nothing at runtime, but they only work in browsers and only when delivered as real response headers; a CSP placed in a meta tag, for example, ignores frame-ancestors and reporting directives, and HSTS or X-Frame-Options in meta tags are ignored entirely.

Strict-Transport-Security (HSTS, RFC 6797) tells the browser to use HTTPS only for the host for max-age seconds, turning a mistyped http:// link or a downgrade attempt on hostile Wi-Fi into an automatic HTTPS request. A typical value is 'max-age=31536000; includeSubDomains'. Adding 'preload' and submitting the domain to the browser preload list protects even the very first visit, but the list requires a valid certificate, an HTTP-to-HTTPS redirect on the same host, HTTPS on every subdomain, includeSubDomains and a max-age of at least one year, and removal takes months.

Content-Security-Policy (CSP Level 3, W3C) restricts where scripts, styles, images, frames and connections may load from. A policy such as "default-src 'self'; script-src 'self' 'nonce-r4nd0m' 'strict-dynamic'; object-src 'none'; base-uri 'none'; frame-ancestors 'self'" blocks most injected scripts, whereas policies that allow 'unsafe-inline' or broad schemes like https: offer little XSS protection. The frame-ancestors directive is the modern replacement for X-Frame-Options (RFC 7034), which only supports DENY and SAMEORIGIN; browsers that understand frame-ancestors give it precedence, but sending both remains common for older clients and scanners.

Several smaller headers close specific gaps. X-Content-Type-Options: nosniff stops browsers from guessing MIME types, so an uploaded text file cannot be executed as script. Referrer-Policy controls how much of the URL leaks to other sites; strict-origin-when-cross-origin, the default in current browsers, sends only the origin cross-site. Permissions-Policy (the successor to Feature-Policy) disables powerful features such as camera=(), microphone=() or geolocation=() for the page and its iframes. Cross-Origin-Opener-Policy, Cross-Origin-Embedder-Policy and Cross-Origin-Resource-Policy isolate the page from other origins and are required for features like SharedArrayBuffer. X-XSS-Protection, by contrast, controlled a filter that modern browsers removed and that could itself be abused, so current guidance is to omit it or send 0.

This tool requests the URL, following up to five redirects, and requires a successful 2xx response. On HTTPS URLs a missing HSTS header is a critical issue, and max-age below 31536000 is a warning. CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy and Permissions-Policy (or legacy Feature-Policy) each produce a warning when absent. COOP, COEP and CORP count as bonus passes. The grade is the share of passed checks out of seven: A from 90 percent, then B, C and D in ten-point steps, and F below 60 percent.

Common Errors and How to Fix Them

ProblemHSTS is present with max-age=3600 or 86400, so protection lapses after an hour or a day without visits.
FixUse 'Strict-Transport-Security: max-age=31536000; includeSubDomains'. Ramp up from a short value only while confirming every subdomain serves HTTPS, and add 'preload' only when you are ready to submit the domain to the preload list.
ProblemHeaders configured in the nginx server block disappear on some paths, or on 404 and 500 pages.
Fixnginx inherits add_header only when the current level defines none of its own, and without the 'always' parameter it skips error responses. Use 'add_header ... always;' and repeat the full set in any location block that adds its own headers, or use a shared include file.
ProblemA CSP exists but contains 'unsafe-inline', 'unsafe-eval' and https:, so it passes this check while blocking almost nothing.
FixMove to nonce- or hash-based scripts with 'strict-dynamic', set object-src 'none' and base-uri 'none', and roll out with Content-Security-Policy-Report-Only first to collect violations before enforcing.
ProblemThe site still sends 'X-XSS-Protection: 1; mode=block' and the team treats it as XSS defence.
FixThe browser filter behind this header was removed and could itself introduce information leaks. Send 'X-XSS-Protection: 0' or omit it, and invest in a real CSP instead.
ProblemBoth the application and the reverse proxy add a Content-Security-Policy header, and some scripts suddenly stop loading.
FixWhen several CSP headers arrive, the browser enforces all of them, so a resource must satisfy every policy. Define the policy in a single layer and remove the duplicate.
ProblemThe checker fails with an HTTP 403 even though the site opens fine in a browser.
FixThis tool needs a 2xx response to grade headers. A WAF or bot-protection rule is likely blocking automated clients; allow the request or test a public page that returns 200, and make sure the same headers are applied there.

Frequently Asked Questions

Should I use X-Frame-Options or CSP frame-ancestors?

Use frame-ancestors as the primary control because it supports multiple allowed origins and modern browsers give it precedence. Keep X-Frame-Options: DENY or SAMEORIGIN alongside it for older clients and because many audits, including this one, still look for the header. Make sure both express the same intent so legitimate embedding is not blocked by one and allowed by the other.

What are the requirements for HSTS preload?

You need a valid certificate, a redirect from HTTP to HTTPS on the same host, HTTPS working on every subdomain, and an HSTS header on the base domain containing max-age of at least 31536000, includeSubDomains and preload. Submission is then reviewed for inclusion in browsers. Be careful: getting removed takes months, and any internal HTTP-only subdomain becomes unreachable.

Why is my grade lower than I expected?

The grade divides passed checks by seven. HSTS, CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy and Permissions-Policy each count once, and COOP, COEP and CORP add extra passes. Missing two of the core headers usually drops a site to C or D. Missing HSTS on an HTTPS URL is flagged as a critical issue regardless of the grade.

Do security headers improve SEO rankings?

Not directly. Search engines do not rank pages on the presence of CSP or Referrer-Policy. HTTPS itself is a lightweight ranking signal, and HSTS helps by preventing insecure duplicates. The real benefit is indirect: fewer injected scripts, no malicious iframes and no security warnings that could get a site flagged or erode visitor trust.

Which Referrer-Policy value should I choose?

strict-origin-when-cross-origin is a sound default: full URLs within your own site, only the origin to other HTTPS sites and nothing on downgrade to HTTP. Choose no-referrer or same-origin for pages whose URLs contain tokens or personal data, such as password-reset or account pages. Avoid unsafe-url, which leaks complete URLs everywhere.

Academic Documentation

Protocol context and primary references

REST API Documentation

v1.0
GET /api/tools/security-headers
					curl -X POST https://epcybertools.com/api/tools/security-headers \
  -H "Content-Type: application/json" \
  -d '{"url":"https://google.com"}'
				
					{
  "success": true,
  "results": [
    { "test": "Sample Check", "status": "pass", "message": "All clear" }
  ]
}
				
Rate Limit: 100 requests / 15 minutes
100-Day Max Lifespan
155d 5h 21m 8s
PQC Migration Target
1178d 5h 21m 8s