Quick Note
Focused tool workspace
HTTP Observatory

Run a Mozilla-style HTTP security header audit for HTTPS, HSTS, CSP, framing, and browser isolation policies.

Free to useBrowser-basedFast workflows
Sponsored
Security header scan

Scan HTTP response headers without leaving the browser workspace

Check HTTPS delivery, HSTS, Content-Security-Policy, framing protection, Referrer-Policy, and cross-origin isolation headers in one report. The grading model is observatory-style, practical, and built for fast triage.

Live server-side scanHeader-by-header recommendationsSEO-friendly report page
Checks
12

Weighted security checks

Focus
Headers

Transport, policy, and browser isolation

Workflow
Fast

Paste a URL and scan in seconds

Scan target

Run the observatory scan

This tool runs a live header request and follows redirects. The scoring model is observatory-style and practical, but it is not an official Mozilla / MDN Observatory score.

Result

Grade and transport summary

Run a scan to get a grade, redirect details, and a header-by-header audit report.

Findings

Priority issues and recommendations

After scanning, the top failing and warning checks appear here first so you can fix the most important issues without digging through raw headers.

Full report

All checks

The full check list appears here after the first scan.

Raw headers

Response header output

Raw response headers appear here after the scan completes.