Security Headers Checker
Score whether a response sends HSTS, CSP, nosniff, clickjacking protection and Referrer-Policy — not a ranking trick.
What this tool gives you
Check security headers
Fetch a public page or paste response headers. The checker scores HSTS, CSP, nosniff, clickjacking and Referrer-Policy — browser hygiene, not a ranking trick.
What this checker looks for
HSTS. CSP. nosniff. X-Frame-Options or frame-ancestors. Referrer-Policy.
HSTS
Strict-Transport-Security with a long max-age keeps HTTPS sticky.
CSP
Content-Security-Policy limits scripts and frames. Report-Only is a staging step.
nosniff
X-Content-Type-Options: nosniff stops MIME sniffing.
Clickjacking
X-Frame-Options DENY/SAMEORIGIN or CSP frame-ancestors.
Referrer-Policy
Prefer strict-origin-when-cross-origin. Never unsafe-url.
Not a ranking lever
This is browser security hygiene, not a citation trick.
How to use the checker
Fix HTTPS first, then HSTS, then CSP and framing.
Check the live response
Fetch the public URL or paste headers from curl -I.
Turn on HSTS
Send Strict-Transport-Security with max-age of at least 180 days.
Lock scripts and frames
Add CSP, nosniff, clickjacking protection and Referrer-Policy.
What security headers usually include
Response headers that tell browsers how to treat HTTPS, scripts, framing and referrers.
| Header | Job | Default for public sites |
|---|---|---|
| HSTS | Keep HTTPS sticky | max-age at least 15552000 |
| CSP | Limit scripts and frames | Enforcing policy, not only Report-Only |
| nosniff | Stop MIME sniffing | X-Content-Type-Options: nosniff |
| Framing | Block clickjacking | DENY, SAMEORIGIN or frame-ancestors |
| Referrer-Policy | Limit URL leakage | strict-origin-when-cross-origin |
| Never | unsafe-url referrers | Do not leak full URLs cross-origin |
Related GEO pages
Fix security headers, then mixed content, then outbound HTTPS links.
Mixed Content Checker
Score http:// scripts, styles, images and form actions on HTTPS pages.
Redirect Checker
Score 301/308 hops, HTTPS Location, chains and loops.
External Link Checker
Score HTTPS outbound hrefs, descriptive anchors and new-tab noopener.
Canonical URL Checker
Score one absolute HTTPS rel=canonical and matching og:url.
XML Sitemap Checker
Score sitemap.xml loc hygiene: HTTPS URLs, unique paths and lastmod.
Robots Meta Checker
Score meta robots and X-Robots-Tag index/noindex hygiene.
Favicon Checker
Score rel=icon href, type, sizes and apple-touch-icon tab-icon hygiene.
Open Graph Checker
Score og:title, og:description, HTTPS og:image and matching og:url.
GEO Visibility Checklist
Score citation-ready content, entity clarity and weekly mention tracking.
Tools Lab
More generators, calculators and GEO workflows.
Security headers FAQs
Do security headers help ChatGPT cite my page?
No. Security headers protect browsers. Citations still depend on crawl access, answer-ready content and corroboration.
Which headers does this checker score?
Strict-Transport-Security, Content-Security-Policy, X-Content-Type-Options, X-Frame-Options or CSP frame-ancestors, and Referrer-Policy.
Is a missing CSP always a fail?
Yes for the score. Report-Only counts as a warning. Ship an enforcing policy when the site can take it.