SEOTools.info / Tools / Security Headers Checker
Security Headers Checker
Check whether a site sends key security headers: HSTS, CSP, X-Frame-Options, X-Content-Type-Options and more.
We check 9 recommended security headers.
Next step: SSL Certificate Checker →
About the Security Headers Checker
Scans a URL for the security headers that protect visitors from common attacks — clickjacking, XSS, protocol downgrade and more. Missing headers are easy wins for a safer, more trustworthy site.
What this tool checks
- Checks 9 recommended security headers
- Shows which are present and their values
- Gives a quick pass/fail overview
The security headers we check
| Header | What it protects against |
|---|---|
| Strict-Transport-Security | Forces HTTPS, blocks protocol-downgrade attacks. |
| Content-Security-Policy | Limits which scripts/resources can load — stops XSS. |
| X-Frame-Options | Prevents clickjacking via iframes. |
| X-Content-Type-Options | Stops MIME-type sniffing. |
| Referrer-Policy | Controls how much referrer data leaks. |
| Permissions-Policy | Restricts access to camera, geolocation, etc. |
Frequently asked questions
Do security headers affect SEO?
Not directly, but HTTPS + strong headers build trust and protect users, which supports overall site quality.
Where do I add these?
In your server or CDN config (nginx, Apache, Cloudflare) — they're response headers, not page content.
Track this across every page automatically
Search Console, rank tracking and site monitoring in one panel — free account, no card.