Skip to content
ForgePlug — Logo
developerRuns Server-SideNo Signup

Security Headers Checker

Fetches a domain and inspects its response for the six HTTP security headers browsers rely on for defense-in-depth: Strict-Transport-Security, Content-Security-Policy, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, and Permissions-Policy. Each missing or misconfigured header comes with a plain-English explanation of exactly what it protects against — no jargon-only output. Part of ForgePlug's Site Health Check, which also runs SSL, DNS, and robots.txt checks on the same domain at no extra cost.

This check runs server-side — ForgePlug briefly connects to the domain you enter to read its certificate, DNS records, response headers, and robots.txt/sitemap. We don't store anything beyond a 5-minute result cache (to avoid re-running the same check for everyone hitting a trending domain) and a short-lived snapshot used to compare a re-check later.

The six headers this scanner checks, and what each one stops

Plain-English explanations, not just a list of names.

  • Strict-Transport-Security — forces browsers to use HTTPS on every future visit, closing the window for downgrade/man-in-the-middle attacks on public Wi-Fi.
  • Content-Security-Policy — restricts which scripts and resources a page is allowed to load, limiting the damage if an XSS bug ever gets injected.
  • X-Frame-Options — stops your site from being loaded inside an invisible iframe on another site and used for clickjacking.
  • X-Content-Type-Options — stops browsers from guessing (MIME-sniffing) a file's type, which can otherwise turn an innocuous upload into executable script.
  • Referrer-Policy — controls how much of your URL (which can contain tokens or query data) leaks to third-party sites via the Referer header.
  • Permissions-Policy — explicitly restricts which browser features embedded content is allowed to request, like camera, microphone, or geolocation.

Because it's part of ForgePlug's full Site Health Check, submitting also runs a TLS certificate check, a DNS propagation check, and a robots.txt/sitemap validation on the same domain — all in parallel, at no extra cost.

Frequently Asked Questions

HTTP security headers, explained

Which six headers does this check for?
Strict-Transport-Security, Content-Security-Policy, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, and Permissions-Policy — the standard set browsers use for defense-in-depth against downgrade attacks, XSS, clickjacking, MIME-sniffing, and referrer leakage.
My header is present — why is it still flagged?
A header can be present but misconfigured. This tool flags an HSTS header set to max-age=0 (which disables it) and an X-Frame-Options value other than DENY or SAMEORIGIN, since those are common copy-paste mistakes that leave the protection effectively off.
Is this really free, and is there a limit?
Yes — Site Health Check is free and doesn't require an account. Like every ForgePlug tool it's rate-limited per IP address (a handful of checks per minute) to keep the service fast and available for everyone, not to push a paid tier.
Why does this tool need a server? Aren't ForgePlug's tools all browser-based?
Almost all of them are — but a browser can't open a raw TLS handshake, query a DNS resolver directly, or fetch another site's headers without hitting CORS. Those three things require a real network connection from a server, so this one tool runs a small, rate-limited check server-side instead of pretending it can do it client-side.
What do you do with the domain I check?
The check result is cached for 5 minutes so a burst of people checking the same trending domain doesn't trigger five fresh outbound connections each time, and the most recent result is kept briefly so a re-check can eventually show what changed. We don't log who checked what.
Can I check an internal or private server?
No — the tool refuses any hostname that resolves to a private, loopback, or link-local address (including cloud metadata endpoints) as a security precaution. Enter a public domain name, not an internal hostname or a bare IP address.
What does the overall pass/warn/fail badge mean?
It's the worst result across all four panels, not an average: two or more failing panels caps the overall badge at fail, one failing panel caps it at warn, and any warning (with no failures) also shows as warn. A clean pass means all four checks came back clean.

Guides & Articles

Learn how to get the most out of this tool with our in-depth guides.

Was this tool helpful?

Your feedback helps us improve Security Headers Checker for everyone.

Share this tool

Share