October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsSlow PC?RecommendedPC slow today? Run a repair scan before it gets worseResolve common Windows issues and optimize system performance.Scan NowOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
Content-Security-Policy

CSP Test: How to Check and Safely Test a Content Security Policy Header

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

To check a Content Security Policy (CSP), inspect the HTTP response that your server sends, then observe browser violations while the site runs. To test a proposed change without blocking resources, send it as Content-Security-Policy-Report-Only with a reporting destination. A policy pasted into an evaluator is useful for finding weaknesses, but it does not prove that a live site delivers that policy.

What a CSP test actually needs to prove

CSP is delivered in an HTTP response header. The browser enforces the Content-Security-Policy header it receives, not a policy stored in a source-control file or pasted into a checker. A useful test therefore separates two questions:

  • Delivery: Does the intended response contain the expected header and value?
  • Behavior: What does the browser block or report when real pages and user flows run?

Use a policy evaluator as a third, advisory check. Google’s CSP Evaluator reviews supplied policy text for weaknesses that affect CSP’s value as a cross-site-scripting mitigation. Google states that the tool is provided for convenience and gives no guarantees or warranties; it cannot confirm what your server sends or how every page behaves.

Check the live CSP response header

With cURL

Request headers only, following redirects so you can see the final document response:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
curl -I -L https://example.com/

Look for a line beginning Content-Security-Policy:. For a page that requires a GET request or has unusual redirect behavior, use:

curl -sS -D - -o /dev/null -L https://example.com/

Check the final response as well as redirects: a policy on an intermediate response does not necessarily describe the HTML document that the browser renders. Test representative routes, not only the home page.

In browser developer tools

  1. Open the page in Chromium, Firefox or another modern browser.
  2. Open Developer Tools and select Network.
  3. Reload with the network panel open.
  4. Select the document request (usually the first request with type document).
  5. In Headers, expand Response Headers and read Content-Security-Policy and, if present, Content-Security-Policy-Report-Only.
  6. Use the Console to find CSP violation messages, which identify blocked resource types, URLs and directive names.

Inspect the document response rather than an asset such as a JavaScript file. Also check responses from authenticated areas, API-driven pages and error routes if those are in scope.

Test a policy safely with report-only mode

Serve the candidate policy in a Content-Security-Policy-Report-Only response header:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Content-Security-Policy-Report-Only: default-src 'self'; script-src 'self' https://cdn.example; object-src 'none'; report-to csp-endpoint

The browser reports violations for this candidate but does not use it to block the reported resources. This lets you exercise pages before changing enforcement. If an enforced Content-Security-Policy header is also present, that existing policy continues to block according to its own rules while the report-only policy generates additional reports.

Report-only is an HTTP response-header feature. You cannot deliver it with a <meta> element.

Add a reporting endpoint

MDN documents the Reporting-Endpoints response header and the policy’s report-to directive:

Reporting-Endpoints: csp-endpoint="https://reports.example.net/csp"
Content-Security-Policy-Report-Only: default-src 'self'; report-to csp-endpoint

Configure the endpoint to accept the report format your deployment expects, protect it from unauthorised use, and monitor its volume. MDN notes that report-to should be specified for reports to have an effect. Browser support is not uniform, so MDN describes report-uri as deprecated but says it may be sent alongside report-to for compatibility:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Content-Security-Policy-Report-Only: default-src 'self'; report-to csp-endpoint; report-uri https://reports.example.net/csp

Recheck compatibility for the browsers and deployment date that matter to your audience before relying on one reporting mechanism.

Exercise meaningful coverage

  1. Open the home page and key landing pages.
  2. Sign in and test forms, checkout, search, file upload and other state-changing flows in a safe environment.
  3. Trigger lazy-loaded images, embedded frames, analytics, payment widgets and third-party scripts used by the application.
  4. Review browser console messages and received reports.
  5. Classify each violation as a required dependency, an obsolete resource, an environment-only URL or a policy mistake.
  6. Adjust the candidate policy, repeat the flows and only then plan enforcement.

A single page load cannot exercise every route or user action. Keep report-only active long enough to cover scheduled jobs, less-used screens and different user roles.

Understand CSP directives before changing them

Start with a restrictive baseline and add only sources the application genuinely needs. Common directives include:

  • default-src supplies a fallback for fetch directives that are not set explicitly.
  • script-src controls JavaScript sources; inline code and dynamic evaluation need separate, deliberate treatment.
  • style-src, img-src, font-src and connect-src cover styles, images, fonts and network connections.
  • frame-src controls frames your page loads, while frame-ancestors controls which sites may embed your page.
  • object-src 'none' disables legacy plugin content when it is not required.
  • base-uri 'self' and form-action 'self' restrict base URLs and form destinations.

Do not treat every report as permission to add a broad wildcard. A third-party host may serve multiple unrelated resources, change without notice or be unnecessary on the affected route. Prefer the narrowest origin, nonce, hash or other mechanism that fits the application, and document why each exception exists.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Compare the three checks

Check Evidence Best use What it cannot prove
Live header and browser behavior The response actually returned and violations observed during use Confirming deployment and finding site-specific breakage One session may miss routes and flows
Report-only policy Browser reports for a candidate policy while current enforcement remains Finding required sources before enforcement It does not block the candidate resources
Google CSP Evaluator The policy text supplied to the tool Spotting likely weaknesses and unsafe patterns It does not verify delivery or guarantee protection

Promote a tested policy to enforcement

  1. Keep the candidate in report-only mode while correcting genuine violations.
  2. Confirm the final header appears on every intended HTML response, including redirects and authenticated routes.
  3. Deploy Content-Security-Policy with the reviewed directives.
  4. Retain reporting where practical so regressions are visible.
  5. Watch error rates and user-critical flows immediately after rollout; be ready to revert the header if a required dependency was missed.

Remember that a report-only header does not weaken an already enforced policy, and removing a report-only header does not remove enforcement from a separate normal CSP header.

Common CSP testing failures and fixes

No CSP header appears

Cause: You inspected the wrong response, a redirect, a cached variant or a route configured differently. Fix: Use the document request in DevTools and curl -sS -D - -o /dev/null -L; test the exact hostname, scheme and route users receive.

The evaluator says the policy is strong, but the site is unprotected

Cause: The evaluator saw pasted text, not the server response. Fix: verify the live header and browser behavior separately.

Report-only produces no reports

Cause: No reporting destination, an incorrect endpoint name, unsupported browser behavior or an endpoint that rejects the report format. Fix: send Reporting-Endpoints, reference the exact name with report-to, inspect network/server logs and consider the compatibility fallback documented by MDN.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Resources are blocked even though the new policy is report-only

Cause: A separate enforcing CSP is active. Fix: inspect all CSP response headers; remember that report-only adds reports but does not override enforcement.

Adding every reported host makes the policy huge

Cause: Reports were copied into allowlists without reviewing necessity. Fix: trace each request to application code, remove obsolete dependencies and scope unavoidable third parties as narrowly as possible.

Works in one browser but not another

Cause: Reporting and newer directives have differing compatibility. Fix: test the browsers you support and consult the current MDN header documentation before choosing a reporting fallback.

Performance, reliability and operational notes

  • Header inspection is cheap, but full confidence requires automated requests for important routes plus browser tests for dynamic flows.
  • Reports can be noisy: extensions, transient third-party failures and repeated page loads may obscure actionable violations. Aggregate by directive, URL, route and release.
  • Do not include sensitive query strings or user data in a reporting pipeline without reviewing your privacy and retention requirements.
  • Test through the same CDN, proxy and authentication layers used in production; any layer that rewrites headers can change the result.
  • Cache variation matters. If policy differs by tenant, locale or user state, ensure cache keys and response headers cannot mix policies.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Or skip the browser setup

For repeatable visual checks of pages while you test headers, ScreenshotNeo provides a website screenshot API. It accepts a URL in one request and can capture PNG, JPEG, WebP or PDF. Before capture it accepts cookie/consent banners and removes more than 60 known consent platforms, newsletter popups and chat widgets; each cleanup step can be turned off. Bot checks or CAPTCHAs, blank pages, timeouts, failed loads and cache hits are not billed, and response headers identify the page verdict and billing result. Its MCP server exposes take_screenshot, get_page_info and capture_pdf to Claude, Cursor and other MCP clients.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

One-call example (see the ScreenshotNeo docs for all options):

Best Value
Sale
The Web Application Hacker's Handbook: Finding and Exploiting Security Flaws
  • Comes with secure packaging
  • It can be a gift item
  • Easy to read text
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://example.com -o shot.webp

Python:

import requests
r = requests.get("https://api.screenshotneo.com/v1/shot", params={"access_key": "YOUR_API_KEY", "url": "https://example.com"}, timeout=90)
open("shot.webp", "wb").write(r.content)

Node.js:

const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://example.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);

The Free plan includes 1,000 screenshots a month with no card; paid plans start at $5 for 3,000. Create a free ScreenshotNeo account.

FAQ

Can I test CSP with a meta tag?

No. Report-only testing requires the HTTP response header; a meta element cannot deliver Content-Security-Policy-Report-Only.

Should report-only replace my enforced CSP?

No. Send it alongside the enforced policy when you need to evaluate an additional candidate without changing current blocking behavior.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Is a policy evaluator a security certification?

No. It is an advisory review of supplied text. Verify the deployed header and run representative browser flows.

Frequently Asked Questions

Can I test CSP with a meta tag?

No. Report-only testing requires the HTTP response header; a meta element cannot deliver Content-Security-Policy-Report-Only.

Should report-only replace my enforced CSP?

No. Send it alongside the enforced policy when you need to evaluate an additional candidate without changing current blocking behavior.

Is a policy evaluator a security certification?

No. It is an advisory review of supplied text. Verify the deployed header and run representative browser flows.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The Bottom Line

Inspect the live response first, test proposed directives with Content-Security-Policy-Report-Only and reporting, then enforce only after real routes and user flows are clean.

Quick Recap

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Read next

Recommended PC Tool
Recommended PC Tool
PC Slower Than It Used to Be?Free scan - under a minute
Crashes, No Sound, or Screen Glitches?Free driver scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.