WatchCron

Security Headers Checker

Enter a URL to analyze its HTTP security headers and get a security grade.

✗
Security Headers

What security headers actually protect against

Security headers are server-side instructions that tell browsers what to allow and what to block. They sit in the HTTP response, invisible to visitors but critical for defense. Strict-Transport-Security (HSTS) forces HTTPS and prevents protocol downgrade attacks. Content-Security-Policy (CSP) controls which scripts, styles, and resources can load, making it the single most effective defense against cross-site scripting. X-Frame-Options stops your pages from being embedded in iframes on malicious sites, which is how clickjacking works.

Three more headers round out the baseline. X-Content-Type-Options: nosniff prevents browsers from guessing file types and executing a disguised script. Referrer-Policy limits what URL information leaks when users click outbound links. And Permissions-Policy restricts access to browser APIs like camera, microphone, and geolocation so compromised scripts can't abuse them.

Why sites fail this check (and how to fix it)

Most sites score poorly not because they chose to skip security headers, but because nobody configured them. Headers live in web server config (Nginx, Apache), CDN settings (Cloudflare, Fastly), or application middleware, not in application code. A fresh server install ships with none of them. Migrating to a new hosting provider or swapping your CDN can quietly drop headers that were present before.

Fixing a low grade usually takes minutes. HSTS, X-Content-Type-Options, and Referrer-Policy are one-line additions that won't break anything. X-Frame-Options is safe unless you intentionally embed your site in iframes elsewhere. CSP requires more care because a restrictive policy can block legitimate scripts, so start with Content-Security-Policy-Report-Only to log violations before enforcing. Confirm your certificate is valid with the SSL checker before enabling HSTS; HSTS on an expired cert locks visitors out entirely. You can verify the full response header set using the HTTP headers checker.

One check is not enough

Headers can disappear without warning. A deploy overwrites your Nginx config. A CDN rule update strips a header that was present for months. A load balancer change drops HSTS from responses while the site keeps serving pages normally. You won't see a visual difference, and neither will your users. But the protections vanish, and the window for exploitation opens quietly.

WatchCron's uptime monitoring checks your endpoints on a schedule and alerts your team through Slack, email, SMS, or other channels when something changes. Use this tool to audit your headers now, then set up monitoring so a missing header triggers a notification instead of sitting unnoticed until the next quarterly scan.

Start monitoring in under 2 minutes

Free plan includes 20 checks. No credit card required.

Get Started Free Free plan · 20 checks forever