Home/Guides/How to Check HTTP Security Headers on a Website
HTTP security guide

How to Check HTTP Security Headers on a Website

Security headers are browser instructions carried in an HTTP response. Check the values actually returned by the production URL, then interpret each policy in the context of the application.

Short answer

Fetch the response headers for the exact page you want to inspect and review security policies such as HSTS, Content-Security-Policy, X-Content-Type-Options, Referrer-Policy and Permissions-Policy. Smart Web Utility's HTTP Header Checker shows the full response-header map rather than reducing security to a single grade.

Headers worth reviewing

Strict-Transport-Security

HSTS tells supporting browsers to use HTTPS for future requests to the host for the configured max-age. It should be delivered over HTTPS and deployed carefully before broad subdomain or preload settings are used.

Content-Security-Policy

CSP controls which resource origins and script/style execution patterns a page allows. Merely having a CSP header is not enough; an overly broad policy can provide little protection.

X-Content-Type-Options

nosniff tells browsers to respect declared MIME types instead of trying to infer another type, reducing MIME-confusion risks.

Referrer-Policy

This policy controls how much referrer information a browser includes when navigating or requesting resources, especially across origins.

Also inspect Permissions-Policy and framing controls

Permissions-Policy can restrict access to browser features. Framing protections may be expressed with X-Frame-Options or the more flexible CSP frame-ancestors directive. Which policies are appropriate depends on whether the application intentionally supports embedding or specific browser capabilities.

Why this tool does not assign a security grade

Presence alone cannot prove a policy is safe. A CSP can be present but permissive; an HSTS policy can be inappropriate for a host that is not ready to force HTTPS across subdomains. A meaningful review needs both the raw value and knowledge of the application architecture.

Check the response users actually receive

Headers can differ by path, CDN edge, authentication state, cookies, redirect target and application route. Test important production URLs individually. If the first URL redirects, inspect the redirect chain as well as the final response because policies can change between hops.

Primary references

Last technically reviewed: September 28, 2026.