Missing headers are exactly what Shield enforces automatically on every protected site. See plans →

Free Website Security Headers Checker

Grades any public website on the security headers attackers check first — HSTS, Content-Security-Policy, clickjacking defences, MIME-sniffing, referrer and permissions policies — plus TLS version and certificate expiry. No signup, results in seconds.

Got a B, C or F?

Every failing header above is enforced automatically on Shield-protected sites — plus L3/L4/L7 filtering, WAF auto-banning and a live block dashboard. Free 14-day pilot on one of your servers, no card required.

Security headers, explained

What are security headers?

HTTP response headers that tell browsers how to handle your site securely — blocking clickjacking, MIME-sniffing attacks, insecure upgrades and unwanted data sharing. They cost nothing and take minutes to add.

Why do they matter?

Missing headers are among the most common findings in security audits and compliance reviews (Cyber Essentials, PCI DSS, GDPR technical measures). Attackers fingerprint unprotected sites automatically.

What does this checker test?

Strict-Transport-Security (HSTS), Content-Security-Policy, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, plus TLS version and certificate expiry.

What score should I aim for?

A or A+. Anything lower means browsers are missing instructions they need — each failed check above tells you exactly which header to add.

Do I need to sign up?

No. Enter any public website address and get graded instantly, with no account and no email required.

Embed this checker

Free for any website. Copy, paste, done — with a link back to us.

<iframe src="https://streammaster.co.uk/shield/tools/headers?embed=1" width="100%" height="560" style="border:0;border-radius:12px;" loading="lazy" title="Security Headers Checker by 9Gen Media Shield"></iframe>