SECURITY HEADER CHECKER

Audit security headers across your site

Inspect HSTS, CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, and Permissions-Policy at every hop in a redirect chain, not just the final response.

Which security headers matter

Strict-Transport-Security (HSTS)

Forces HTTPS for returning visitors. Without it, browsers will still try HTTP first and rely on a redirect.

Content-Security-Policy (CSP)

Controls what resources a page can load. Prevents XSS and data injection attacks. Often deployed loosely and never revisited.

X-Frame-Options

Prevents clickjacking by controlling whether a page can be embedded in an iframe.

X-Content-Type-Options

Prevents MIME-type sniffing. Should be set to nosniff.

Referrer-Policy

Controls how much referrer information is sent when navigating away from a page.

Permissions-Policy

Controls access to browser features like camera, microphone, and geolocation.

Why auditing headers in bulk matters

One page can have the right headers while others do not. Different server configurations, CDN edge rules, and CMS templates can produce inconsistent headers across a site. The only way to know is to check a real sample, not just the homepage.

Batch check a representative set of URLs and compare headers across them.

What checkredirects.io shows

For each URL, response headers are captured at every hop. Security headers are surfaced alongside redirect chain data, TLS certificates, and timing. This means you can check whether your 301 redirect responses themselves are missing security headers (they often are), not just the final page.

Common findings in a security header audit

Frequently asked questions

What is a security header checker?

A tool that inspects HTTP response headers on a URL and reports which security-related headers are present, missing, or misconfigured. checkredirects.io checks headers at every hop in a redirect chain, not just the final response.

Do redirect responses need security headers?

They should have them. A 301 or 302 response still sends headers to the browser. If HSTS is missing on the redirect hop, the browser does not learn to use HTTPS until it reaches the final page.

Can I audit security headers in bulk?

Yes. Submit up to 500 URLs in a batch and review security headers for each one. Filter and export the results.

Is this a replacement for a penetration test?

No. A header audit is one layer of a security review. It tells you whether basic protections are in place. It does not test for application-level vulnerabilities.

Check security headers across your URLs

Batch up to 500 URLs, see which headers are present at each hop, export the gaps.

Get started free →