Security header grade
A letter grade based on the presence of HSTS, CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, and Permissions-Policy.
Enter a URL to see its HTTP response headers and get a security grade based on the presence of HSTS, CSP, X-Frame-Options, and other hardening headers.
Start your 7-day trial — no credit card, free plan after.
Enter a URL (or domain). NorthDuty requests it and reports the response headers and a security-header grade.
Free check. No signup. Results are not published or indexed.
Enter a URL (or domain). NorthDuty requests it and reports the response headers and a security-header grade. Recurring checks are configured inside the NorthDuty app.
A single request shows the response headers and grades the most important security headers.
A letter grade based on the presence of HSTS, CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, and Permissions-Policy.
A clear present/missing breakdown so you know exactly which hardening headers to add.
The final HTTP status after redirects, so you can confirm the URL resolves the way you expect.
Server, Content-Type, Cache-Control, and X-Powered-By — useful context for debugging and fingerprinting risk.
Security headers are cheap to add and meaningfully reduce clickjacking, MIME-sniffing, and downgrade attacks — but they're easy to forget.
No signup — enter a URL and get the headers and grade back.
Provide a full URL or just a domain; NorthDuty defaults to HTTPS.
NorthDuty makes a GET request and reads the response headers, following redirects safely.
Security headers are scored A-F with a present/missing list — no report snapshot is stored.
NorthDuty's health checks include security-header scoring, so regressions are caught on a schedule.
What each one does, and a sane starting value. Test changes on staging first — two of these can break a working site if set carelessly.
| Header | What it prevents | A reasonable starting point |
|---|---|---|
| Strict-Transport-Security (HSTS) | Downgrade attacks and the first insecure request on a repeat visit | max-age=31536000; includeSubDomains — add preload only when you are certain every subdomain is HTTPS |
| Content-Security-Policy | Injected and third-party scripts running on your pages | Start in report-only mode; a strict policy on an existing site takes iteration |
| X-Frame-Options | Clickjacking through your site being framed elsewhere | SAMEORIGIN (or the frame-ancestors directive in CSP) |
| X-Content-Type-Options | Browsers guessing a file's type and running it as script | nosniff |
| Referrer-Policy | Leaking full URLs, including query strings, to other sites | strict-origin-when-cross-origin |
| Permissions-Policy | Scripts quietly requesting camera, microphone or geolocation | Deny what you do not use: camera=(), microphone=(), geolocation=() |
Headers are cheap to add and easy to get subtly wrong.
Preloading is hard to reverse and applies to every subdomain. If one internal subdomain is still HTTP, you have locked yourself out of it in every modern browser.
The first strict policy usually kills analytics, the payment SDK or the page builder's inline scripts. Run it in report-only mode until the reports are quiet.
Nginx or Apache, a plugin, and the CDN can each add headers. Duplicates and conflicts are common after a migration, and the checker shows you what actually arrives.
Some proxies strip or rewrite headers. Test the live public URL, not the origin.
Headers will not save a page that loads mixed content. Fix the assets, then tighten the headers.
Headers disappear in server migrations, plugin updates and CDN config changes — silently, because nothing on the page looks different.
A page with all six headers present is not secure, and a page missing two is not necessarily vulnerable. These headers reduce the blast radius of specific attacks; they do nothing about an outdated plugin, a weak password or an exposed admin endpoint.
Treat the result as a hygiene check: the cheap wins that should simply be switched on, verified after every infrastructure change, and then largely forgotten.
Use the tool preview for a quick answer, then move into recurring monitoring for your most important pages and journeys.
Feature
Learn how NorthDuty combines editable user journeys and website health checks in one website monitoring project.
Explore Website MonitoringFeature
Monitor uptime every 5 minutes by default with HTTP, SSL, DNS, blank-page detection, broken resources, JavaScript errors, and API call tracking.
Explore Uptime MonitoringArticle
Use this 41-point website monitoring checklist to cover uptime, SSL, DNS, forms, checkout, journeys, alerts, launch checks, and incident response.
Read Website Monitoring Checklist: 41 ChecksPricing
NorthDuty plans are sized by how many checkout, signup and login journeys you monitor: Free, $29 Starter, $79 Pro, $199 Business. 7-day trial, no card.
Compare pricing plansAnswers about this diagnostic preview and when to move into recurring monitoring.
Response headers that tell the browser how to treat your page: enforce HTTPS (HSTS), restrict which scripts may run (Content-Security-Policy), refuse framing (X-Frame-Options), stop content-type guessing (X-Content-Type-Options), limit referrer leakage, and deny unused browser features (Permissions-Policy).
X-Content-Type-Options: nosniff, X-Frame-Options: SAMEORIGIN and Referrer-Policy: strict-origin-when-cross-origin are safe to add on almost any site. HSTS is next, without preload at first. Content-Security-Policy last — it is the one that needs iteration in report-only mode.
Usually a server migration, a CDN configuration change or a plugin update. Headers can be set at the origin, by an application plugin and at the proxy; when one layer changes, the arriving set changes with no visible difference on the page.
It requests the public URL you enter, so you see the headers a visitor receives after any CDN or proxy in front of your site — which is the set that actually matters.
Yes. It's free and requires no signup. Enter a URL and you get the response headers and a security grade.
It scores the presence of six key headers — HSTS, Content-Security-Policy, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, and Permissions-Policy — and maps the count to an A-F grade.
No. Headers are one layer. A high grade means good baseline hardening, but real security depends on many other factors.
Yes. It follows redirects safely and reports the headers and status of the final response.
Security headers can disappear in a single deploy. NorthDuty scores them continuously, so a missing CSP or HSTS gets flagged fast.
7 days with Pro features and limits, no credit card — then keep one daily journey on the free plan.