Audit security headers across your site
Inspect HSTS, CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, and Permissions-Policy at every hop in a redirect chain, not just the final response.
Which security headers matter
Strict-Transport-Security (HSTS)
Forces HTTPS for returning visitors. Without it, browsers will still try HTTP first and rely on a redirect.
Content-Security-Policy (CSP)
Controls what resources a page can load. Prevents XSS and data injection attacks. Often deployed loosely and never revisited.
X-Frame-Options
Prevents clickjacking by controlling whether a page can be embedded in an iframe.
X-Content-Type-Options
Prevents MIME-type sniffing. Should be set to nosniff.
Referrer-Policy
Controls how much referrer information is sent when navigating away from a page.
Permissions-Policy
Controls access to browser features like camera, microphone, and geolocation.
Why auditing headers in bulk matters
One page can have the right headers while others do not. Different server configurations, CDN edge rules, and CMS templates can produce inconsistent headers across a site. The only way to know is to check a real sample, not just the homepage.
Batch check a representative set of URLs and compare headers across them.
What checkredirects.io shows
For each URL, response headers are captured at every hop. Security headers are surfaced alongside redirect chain data, TLS certificates, and timing. This means you can check whether your 301 redirect responses themselves are missing security headers (they often are), not just the final page.
Common findings in a security header audit
- HSTS missing on the redirect hop but present on the destination (incomplete protection)
- CSP set to
unsafe-inlineor overly permissive - X-Frame-Options missing on authenticated or form pages
- Headers present on the main domain but missing on subdomains
- Redirect responses (301/302) that strip security headers entirely
Frequently asked questions
What is a security header checker?
A tool that inspects HTTP response headers on a URL and reports which security-related headers are present, missing, or misconfigured. checkredirects.io checks headers at every hop in a redirect chain, not just the final response.
Do redirect responses need security headers?
They should have them. A 301 or 302 response still sends headers to the browser. If HSTS is missing on the redirect hop, the browser does not learn to use HTTPS until it reaches the final page.
Can I audit security headers in bulk?
Yes. Submit up to 500 URLs in a batch and review security headers for each one. Filter and export the results.
Is this a replacement for a penetration test?
No. A header audit is one layer of a security review. It tells you whether basic protections are in place. It does not test for application-level vulnerabilities.
Check security headers across your URLs
Batch up to 500 URLs, see which headers are present at each hop, export the gaps.