Free HTTP & Security Headers Checker

Enter a URL to see its HTTP response headers and get a security grade based on the presence of HSTS, CSP, X-Frame-Options, and other hardening headers.

Start your 7-day trial — no credit card, free plan after.

Check HTTP headers

Enter a URL (or domain). NorthDuty requests it and reports the response headers and a security-header grade.

Free check. No signup. Results are not published or indexed.

How NorthDuty security header monitoring works

Enter a URL (or domain). NorthDuty requests it and reports the response headers and a security-header grade. Recurring checks are configured inside the NorthDuty app.

What this header checker reports

A single request shows the response headers and grades the most important security headers.

Security header grade

A letter grade based on the presence of HSTS, CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, and Permissions-Policy.

Which headers are missing

A clear present/missing breakdown so you know exactly which hardening headers to add.

Response status

The final HTTP status after redirects, so you can confirm the URL resolves the way you expect.

Notable headers

Server, Content-Type, Cache-Control, and X-Powered-By — useful context for debugging and fingerprinting risk.

Why check HTTP headers

Security headers are cheap to add and meaningfully reduce clickjacking, MIME-sniffing, and downgrade attacks — but they're easy to forget.

How the header checker works

No signup — enter a URL and get the headers and grade back.

1

Enter a URL

Provide a full URL or just a domain; NorthDuty defaults to HTTPS.

2

We request the page

NorthDuty makes a GET request and reads the response headers, following redirects safely.

3

You get a graded report

Security headers are scored A-F with a present/missing list — no report snapshot is stored.

4

Keep headers in check

NorthDuty's health checks include security-header scoring, so regressions are caught on a schedule.

The security headers this checker looks for

What each one does, and a sane starting value. Test changes on staging first — two of these can break a working site if set carelessly.

HeaderWhat it preventsA reasonable starting point
Strict-Transport-Security (HSTS)Downgrade attacks and the first insecure request on a repeat visitmax-age=31536000; includeSubDomains — add preload only when you are certain every subdomain is HTTPS
Content-Security-PolicyInjected and third-party scripts running on your pagesStart in report-only mode; a strict policy on an existing site takes iteration
X-Frame-OptionsClickjacking through your site being framed elsewhereSAMEORIGIN (or the frame-ancestors directive in CSP)
X-Content-Type-OptionsBrowsers guessing a file's type and running it as scriptnosniff
Referrer-PolicyLeaking full URLs, including query strings, to other sitesstrict-origin-when-cross-origin
Permissions-PolicyScripts quietly requesting camera, microphone or geolocationDeny what you do not use: camera=(), microphone=(), geolocation=()

Common header mistakes

Headers are cheap to add and easy to get subtly wrong.

HSTS preload before you are ready

Preloading is hard to reverse and applies to every subdomain. If one internal subdomain is still HTTP, you have locked yourself out of it in every modern browser.

A CSP that blocks your own site

The first strict policy usually kills analytics, the payment SDK or the page builder's inline scripts. Run it in report-only mode until the reports are quiet.

Headers set in two places

Nginx or Apache, a plugin, and the CDN can each add headers. Duplicates and conflicts are common after a migration, and the checker shows you what actually arrives.

Assuming the CDN passes them through

Some proxies strip or rewrite headers. Test the live public URL, not the origin.

HTTPS pages serving HTTP assets

Headers will not save a page that loads mixed content. Fix the assets, then tighten the headers.

Never re-checking

Headers disappear in server migrations, plugin updates and CDN config changes — silently, because nothing on the page looks different.

What a header grade does and does not tell you

A page with all six headers present is not secure, and a page missing two is not necessarily vulnerable. These headers reduce the blast radius of specific attacks; they do nothing about an outdated plugin, a weak password or an exposed admin endpoint.

Treat the result as a hygiene check: the cheap wins that should simply be switched on, verified after every infrastructure change, and then largely forgotten.

Go Beyond One-Off Checks

Use the tool preview for a quick answer, then move into recurring monitoring for your most important pages and journeys.

Frequently Asked Questions

Answers about this diagnostic preview and when to move into recurring monitoring.

What are HTTP security headers?

Response headers that tell the browser how to treat your page: enforce HTTPS (HSTS), restrict which scripts may run (Content-Security-Policy), refuse framing (X-Frame-Options), stop content-type guessing (X-Content-Type-Options), limit referrer leakage, and deny unused browser features (Permissions-Policy).

Which security headers should I add first?

X-Content-Type-Options: nosniff, X-Frame-Options: SAMEORIGIN and Referrer-Policy: strict-origin-when-cross-origin are safe to add on almost any site. HSTS is next, without preload at first. Content-Security-Policy last — it is the one that needs iteration in report-only mode.

Why do my headers disappear?

Usually a server migration, a CDN configuration change or a plugin update. Headers can be set at the origin, by an application plugin and at the proxy; when one layer changes, the arriving set changes with no visible difference on the page.

Does this checker test the live site or the origin?

It requests the public URL you enter, so you see the headers a visitor receives after any CDN or proxy in front of your site — which is the set that actually matters.

Is this header checker free?

Yes. It's free and requires no signup. Enter a URL and you get the response headers and a security grade.

How is the security grade calculated?

It scores the presence of six key headers — HSTS, Content-Security-Policy, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, and Permissions-Policy — and maps the count to an A-F grade.

Does a perfect grade mean my site is secure?

No. Headers are one layer. A high grade means good baseline hardening, but real security depends on many other factors.

Does it follow redirects?

Yes. It follows redirects safely and reports the headers and status of the final response.

Start monitoring your website with NorthDuty today.

Security headers can disappear in a single deploy. NorthDuty scores them continuously, so a missing CSP or HSTS gets flagged fast.

7 days with Pro features and limits, no credit card — then keep one daily journey on the free plan.