TheSeoSoul
Free tools/Technical

Free Security Headers Checker

See which HTTP security headers your live URL returns — HSTS, CSP, X-Content-Type-Options, framing, Referrer-Policy, and a few extras. Free, no signup, no fake “security grade” theater beyond a clear presence score.

How it works

  1. 01

    Fetch the live URL

    We follow sensible redirects and read response headers from the final HTML response.

  2. 02

    Score core headers

    HSTS, X-Content-Type-Options, CSP, X-Frame-Options, Referrer-Policy, plus HTTPS, form the core score used in our full audit.

  3. 03

    Surface raw values

    Present headers show their values so you can paste them into your CDN or server config review.

What we check

  • Strict-Transport-Security (HSTS)
  • Content-Security-Policy
  • X-Content-Type-Options
  • X-Frame-Options
  • Referrer-Policy
  • Permissions-Policy / COOP / CORP when present

When to use this checker

Use it after enabling HTTPS, migrating hosts, or tightening a CDN. Pair with the SSL days checker so certificates do not expire silently, and a full audit for crawl and on-page issues.

Frequently asked questions

Which security headers matter for SEO?
HTTPS itself is a ranking and trust baseline. Headers like HSTS, X-Content-Type-Options, and framing policies protect users; broken TLS or mixed content still hurts crawlability and conversions more than a missing CSP.
Does a missing CSP tank rankings?
Usually no — CSP is primarily a security control. Still, sites with weak TLS or mixed HTTP assets can see crawl and UX issues that indirectly hurt SEO.
Do you grade CSP quality?
This tool reports presence and the raw header value. Strength reviews (unsafe-inline, report-only, etc.) are still a human / WAF job.
Is this free?
Yes — free, no registration on TheSeoSoul.

Keep going

What to check next

Headers protect the browser — these tools check crawl and TLS next.

Need the whole picture? Run a full audit · browse every tool.