Security header scan
Scan HTTP response headers without leaving the browser workspace
Check HTTPS delivery, HSTS, Content-Security-Policy, framing protection, Referrer-Policy, and cross-origin isolation headers in one report. The grading model is observatory-style, practical, and built for fast triage.
Live server-side scanHeader-by-header recommendationsSEO-friendly report page
Checks
12
Weighted security checks
Focus
Headers
Transport, policy, and browser isolation
Workflow
Fast
Paste a URL and scan in seconds
Scan target
Run the observatory scan
This tool runs a live header request and follows redirects. The scoring model is observatory-style and practical, but it is not an official Mozilla / MDN Observatory score.
Result
Grade and transport summary
Run a scan to get a grade, redirect details, and a header-by-header audit report.
Findings
Priority issues and recommendations
After scanning, the top failing and warning checks appear here first so you can fix the most important issues without digging through raw headers.
Full report
All checks
The full check list appears here after the first scan.
Raw headers
Response header output
Raw response headers appear here after the scan completes.