HTTP security headers, inspected.
Type a URL, get a per-header readout of what is set, what is missing, and what to change — in plain language with the raw value shown. No score. No dashboard. Just the facts.
Check a URLHeaders checked
Each header is evaluated individually with a plain-language explanation of what it protects against and what to change if it is missing or misconfigured.
How it works
Enter a URL. Headergrade fetches it server-side, follows up to three redirects, and returns each security header found — or notes its absence. Every result includes a plain-language explanation of what the header does, what the current value means, and what to change if it is missing or misconfigured.
No accounts. No data storage. No scheduled scans. The result you see is the result of a single request, reported as received.