StackGrade

Security headers checker

Check HTTPS, HSTS, CSP, clickjacking protection and more for any website, with copy-paste fixes. Free, no signup.

Try: github.com stripe.com bbc.co.uk example.com

What this check looks at

We request a public scan from Mozilla HTTP Observatory and read its test results for seven areas: the HTTP-to-HTTPS redirect, Strict-Transport-Security (HSTS), Content-Security-Policy, clickjacking protection (X-Frame-Options or CSP frame-ancestors), X-Content-Type-Options, Referrer-Policy and cookie flags.

Honest results: if the site blocks the scanner (for example with HTTP 403), or the scan fails or times out, every header shows as Not checked, because the headers it saw may not be what real visitors get. Scans for very popular sites can take up to a minute. Observatory's scan history is public.

Frequently asked questions

Which security headers matter most?

Start with an HTTPS redirect and Strict-Transport-Security (HSTS), then X-Content-Type-Options: nosniff, clickjacking protection (CSP frame-ancestors or X-Frame-Options), and Referrer-Policy. A Content-Security-Policy gives the most protection against cross-site scripting, but takes the most care to set up.

How do I add security headers?

It depends on your host. Cloudflare: Transform Rules > Modify Response Header. Netlify: a _headers file. Vercel: headers in vercel.json. Nginx: add_header lines. Apache: Header set in .htaccess. WordPress hosts often have a security plugin that adds them.

Will a Content-Security-Policy break my site?

It can, if it blocks scripts you rely on. Start with the Content-Security-Policy-Report-Only header to see what would be blocked, then switch to enforcing. StackGrade counts report-only as a warning.

Why does it say "Not checked: HTTP 403"?

The site answered the scanner with an error, which usually means bot protection. The headers in an error page are often different from the real site, so we do not grade them.

Is X-XSS-Protection still needed?

No. Modern browsers removed the XSS auditor, and Mozilla dropped the test. Use a Content-Security-Policy instead.

How StackGrade works

Email authentication · 50 pts

SPF (including the 10-lookup limit), DMARC policy, DKIM keys at common selectors, and MX. These decide whether Gmail and Yahoo trust your mail, and whether scammers can spoof you.

Website security · 35 pts

HTTPS redirect, HSTS, Content-Security-Policy, clickjacking protection, X-Content-Type-Options, Referrer-Policy and cookie flags, using Mozilla's public HTTP Observatory scan.

Domain health · 15 pts

Expiry date and registrar transfer lock from the official registry (RDAP). Domain age, email provider, tech stack and hiring signals are shown but not scored.

Honest by design

If a check can't run (the registry has no RDAP, the site blocks scanners, a lookup times out), we show Not checked with the reason and leave it out of the score. We never guess. The full rubric is public.

Privacy

The checks run in your browser, which asks public services directly: Google Public DNS / Cloudflare DNS, the domain's registry RDAP server, Mozilla HTTP Observatory (its scan history is public) and public job boards (Greenhouse, Lever, Ashby, Workable). For the tech-stack scan, the StackGrade API fetches the site's public homepage; the result is kept briefly in memory, never stored. Graded domains are not logged. Details in the privacy policy. Page views are counted with GoatCounter (open source, no cookies, no personal data); only the page path is sent, never the domain you check.