Enter a URL to check its HTTP security headers.
Analyze security headers (HSTS, CSP, X-Frame-Options, etc.) for any URL using a public CORS proxy. Grades and recommendations included.
Partially — see the note above. In "Fetch URL" mode, the URL you enter is relayed through public CORS proxies to read its response headers. Switch to "Paste Headers" mode to keep everything local.