What security grade does your site get?
Enter a site to check the six key security headers and get an A+ to F grade with fix guidance.
About this tool
HTTP security headers are the cheapest defensive layer on the web: a few lines of configuration that shut down common attacks like clickjacking, script injection and connection downgrades at the root. HSTS locks browsers to HTTPS, CSP blocks foreign scripts, X-Frame-Options forbids rendering your site in an attacker's iframe, and nosniff stops file-type guessing. This tool measures the six key headers and issues a letter grade like securityheaders.com — free and unlimited.
Frequently asked questions
Which headers are checked?
HSTS, Content-Security-Policy, iframe protection (XFO or frame-ancestors), X-Content-Type-Options, Referrer-Policy and Permissions-Policy.
How do I raise my grade?
Add the missing headers in your web server or CDN. HSTS and nosniff are safe one-liners; roll out CSP gradually, starting in Report-Only mode so nothing breaks.
Does an F mean my site will be hacked?
Not necessarily — it means the complementary defense layers are absent, so any other vulnerability becomes easier to exploit. These headers are cheap insurance against that day.
Need help fixing this?
ServerNet's team sets up DNS, email, SSL and servers for you — fast, reliable and fully managed.