Free read-only checker
Free Security Header Checker
A security-header checker requests a public web page and inspects response headers that communicate browser security policies, including HSTS and Content Security Policy where present.
Which headers matter?
Common baseline checks include Strict-Transport-Security, Content-Security-Policy, X-Content-Type-Options, Referrer-Policy, and framing controls. The correct policy depends on application behavior.
Does a missing header prove a vulnerability?
No. It is a configuration observation that needs application context. A present but weak or broken policy may also provide little protection.
How should CSP be introduced?
Inventory required sources, start with a report-only policy where practical, review violations, remove unnecessary sources, and avoid weakening script execution controls merely to silence errors.
What happens after you submit?
The focused checker opens the full Sentryx outside-in report for the submitted domain. The same public scan backend can show related DNS, TLS, host, email-security, and header evidence so a narrow check can lead to a more complete ownership and monitoring decision.