Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

A secure headers test examines the HTTP responses your server actually sends, then checks whether important browser policies are present and appropriate for that page. Test more than the homepage: follow redirects, check both HTTP and HTTPS behavior, and inspect representative application and API paths. Treat the result as a configuration signal—not proof that the site is secure or a complete security audit.

What a secure headers test checks

An HTTP security-header check reads response headers from a real request. It can reveal a missing policy, a policy that is syntactically present but too broad or too restrictive, and differences between routes, redirects, or server layers. A useful test records the requested URL, final URL, status code, redirect chain, and every response in that chain.

Header checks do not replace code review, dependency review, authentication testing, TLS assessment, vulnerability scanning, or review of the browser behavior created by your policy. A scanner only evaluates the responses and rules within its scope. MDN’s HTTP Observatory documentation cautions that API results may not accurately represent an API’s overall security posture, especially when an endpoint behaves differently from a browser-facing page.

The five headers to review first

Header What it controls How to assess it
Content-Security-Policy Which scripts and other resource types a browser may load, plus related embedding and browser behaviors. Check that the policy matches the site’s real scripts, styles, images, connections, frames, and fonts. A copied preset can break legitimate features.
Strict-Transport-Security Whether a browser should use HTTPS for future connections to a host. Confirm it is delivered over HTTPS. Review max-age, and treat includeSubDomains and preload as deliberate, domain-wide choices.
X-Content-Type-Options Whether the browser must respect the MIME type declared by Content-Type. Look for nosniff and verify scripts and styles are served with correct MIME types.
Referrer-Policy How much referring-URL information is sent with outgoing requests. Choose a policy that fits privacy and analytics needs; do not assume a scanner’s preferred value is universal.
Permissions-Policy Whether selected browser features are available to the document and embedded frames. Define only features your application needs and check current browser support. MDN labels this policy experimental.

Content-Security-Policy (CSP)

CSP lets administrators constrain the resources a user agent may load. It can reduce the impact of cross-site scripting, but the policy must describe the application’s actual dependencies. MDN states: “A CSP should be delivered to the browser in the Content-Security-Policy response header.”

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Sale
The Web Application Hacker's Handbook: Finding and Exploiting Security Flaws
  • Comes with secure packaging
  • It can be a gift item
  • Easy to read text

Start with Content-Security-Policy-Report-Only while collecting violations. This observes what would be blocked without breaking production traffic. Inventory legitimate scripts, styles, images, API connections, frames, workers, and fonts; then move to an enforcing policy and continue monitoring. Do not treat upgrade-insecure-requests as a substitute for HSTS.

Strict-Transport-Security (HSTS)

HSTS tells a browser that future connections to a hostname should use HTTPS. Browsers ignore HSTS received over insecure HTTP, so send it on the HTTPS response. It applies to a hostname, not an IP address. includeSubDomains extends the rule to subdomains, which can break a legacy or separately hosted subdomain.

HSTS normally cannot protect the first visit, because the browser has not learned the policy yet. Preloading can reduce that first-connection gap, but it creates broader and harder-to-reverse domain commitments. Confirm every affected subdomain is HTTPS-ready before selecting either option.

X-Content-Type-Options

The useful value is nosniff. It tells the browser to use the advertised MIME type instead of guessing another one. For scripts and styles, a mismatch can cause the browser to block the response. Correct Content-Type values remain essential; adding nosniff does not repair incorrectly typed assets.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Referrer-Policy

Referrer-Policy controls how much URL information accompanies a request. no-referrer sends none. same-origin limits the referrer to same-origin requests. strict-origin-when-cross-origin sends the full URL for same-origin requests, only the origin for qualifying cross-origin HTTPS requests, and nothing when moving from HTTPS to a less secure destination. MDN identifies strict-origin-when-cross-origin as the default when no valid policy is supplied, but explicitly setting a policy makes your intent visible and stable.

Permissions-Policy

Permissions-Policy can allow or deny selected browser features in the document and its frames. The right configuration depends on actual application behavior and browser support. Because the cited MDN documentation labels the feature experimental, avoid presenting one generic allowlist or denylist as a universal best practice.

Run a repeatable command-line test

Use curl to see the response that a client receives. The -I request asks for headers only, while -L follows redirects so you can inspect the final response. Some servers treat HEAD differently from GET; if that happens, use a GET request and discard the body.

curl -I -L https://example.com/

For a GET-style check that preserves the headers and follows redirects:

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
curl -sS -D headers.txt -o /dev/null -L https://example.com/

Open headers.txt and record every status line and header block. Repeat the test for an application route, a static asset, an authenticated endpoint where permitted, and an API endpoint. Compare the HTTP URL as well:

curl -I -L http://example.com/

You should normally see an intentional redirect to HTTPS. Do not infer that the redirected HTTP response had the same security headers as the final HTTPS response; evaluate each response separately.

Inspect headers in browser developer tools

  1. Open the page in a current browser and press F12 (or choose Developer Tools).
  2. Select the Network panel and enable Preserve log so redirects remain visible.
  3. Reload the page, select the document request, and open Headers.
  4. Read Response Headers, then inspect script, stylesheet, iframe, image, and API requests that CSP could affect.
  5. Repeat with a representative route and with the HTTP URL to see the redirect chain.

Developer tools show what that browser received, including policies added or removed by a reverse proxy, CDN, web server, or application framework. A local browser session can also reveal CSP violations in the Console; report-only violations are useful during rollout.

How to interpret scanner findings

Confirm scope before changing configuration

  • Verify the tested hostname, exact URL, response status, and redirect chain.
  • Determine whether the service checked only the homepage or multiple paths.
  • Check whether the tool evaluates headers only, or also TLS, cookies, content, and vulnerabilities.
  • Review how submitted hostnames and scan data are handled before testing private systems.

Separate absence from an unsuitable value

“Missing” means the header was not present on the response examined. “Weak,” “invalid,” or “overly broad” means a value existed but may not provide the intended control. Fixing a missing header is not equivalent to designing a safe CSP or deciding whether subdomains can support HSTS.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Validate behavior after each change

After changing a policy, fetch the same URLs again and test the affected browser behavior. A CSP that blocks a payment script, an HSTS rule that breaks a subdomain, or nosniff that exposes a mis-typed stylesheet is a deployment defect even if a score improves.

A practical remediation workflow

  1. Map responses. List public pages, redirects, static assets, login flows, embeds, and API endpoints. Note which layer generates each response.
  2. Establish HTTPS. Ensure the canonical site and required subdomains work over HTTPS before considering HSTS expansion.
  3. Correct MIME types. Check JavaScript, CSS, fonts, images, and downloads, then add X-Content-Type-Options: nosniff.
  4. Choose referrer handling. Select a policy based on whether paths can contain sensitive identifiers and what cross-origin analytics requires.
  5. Draft CSP from inventory. Use report-only mode, collect violations, remove unnecessary third-party dependencies, and enforce a policy that reflects the remaining resources.
  6. Define feature permissions. Restrict browser features your application does not use, while checking compatibility for your audience.
  7. Retest every route. Verify redirects, cache layers, error pages, API responses, and authenticated paths—not only a successful homepage.

Common failures and fixes

The header appears on the homepage but not on an API

Cause: different application middleware, virtual hosts, or proxy rules generate the responses. Fix: configure the policy at the appropriate shared layer, then test each response class independently.

CSP breaks scripts or styles

Cause: the enforcing policy omitted a legitimate source, nonce, hash, worker, frame, or connection. Fix: switch the proposed policy to report-only, identify the blocked resource in browser reports, and narrow the dependency set before enforcing.

Rank #4
Sale
Bug Bounty Bootcamp: The Guide to Finding and Reporting Web Vulnerabilities
  • Bug Bounty Bootcamp: The Guide to Finding and Reporting Web Vulnerabilities
  • No Starch Press
  • ABIS BOOK

HSTS seems ineffective on the first visit

Cause: the browser has not yet received HSTS over HTTPS. Fix: understand the first-connection limitation; assess preload only after every covered hostname is ready for permanent HTTPS behavior.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

nosniff causes a blank interface

Cause: a script or stylesheet is served with the wrong Content-Type. Fix: correct the server or object-store MIME mapping, purge stale caches, and retest the asset response.

The scanner reports a good score but the site is still vulnerable

Cause: the scan checks a limited set of responses and rules. Fix: combine header testing with application security testing, dependency review, authentication checks, TLS review, and manual verification of sensitive flows.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Reliability, performance, and maintenance

Header tests are inexpensive, but reliability depends on coverage. Automate checks against stable URLs after deployment and at intervals, while allowing expected differences between HTML pages, assets, and APIs. Test through the same CDN, load balancer, and authentication path used by customers. Cache layers can serve an older policy, so include cache invalidation in remediation.

Keep policy decisions under version control. Review third-party scripts and embedded providers whenever they change, because a CSP that was correct last month can become incomplete after a vendor adds a new domain. Recheck HSTS scope before adding subdomains, and monitor report-only CSP violations for noise as well as genuine breakage.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Or skip the browser setup

ScreenshotNeo is not a replacement for reading response headers, but it can give developers a clean visual capture of the page they are validating after header changes. One GET request returns a PNG, JPEG, WebP, or PDF, and its options can wait for a selector or network idle, run custom JavaScript, set headers or cookies, and capture full pages.

With an API key, capture a page like this (see the ScreenshotNeo documentation):

curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp

Cookie and consent banners, newsletter popups, and chat widgets are removed before the shot. Bot checks, blank pages, failed loads, and cache hits are not billed, and each response identifies the result with X-Page-Verdict and X-Billed headers. An MCP server provides take_screenshot, get_page_info, and capture_pdf tools for Claude, Cursor, and other MCP clients. The Free plan includes 1,000 screenshots per month with no card; paid plans start at $5 for 3,000 shots. Create a free ScreenshotNeo account.

Python and Node.js examples

Python

import requests

r = requests.get("https://api.screenshotneo.com/v1/shot", params={"access_key": "YOUR_API_KEY", "url": "https://stripe.com"}, timeout=90)
r.raise_for_status()
open("shot.webp", "wb").write(r.content)

Node.js

const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://stripe.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);
if (!res.ok) throw new Error(`Screenshot failed: ${res.status}`);
const fs = await import('node:fs/promises');
await fs.writeFile('shot.webp', Buffer.from(await res.arrayBuffer()));

Use the capture to confirm that a remediation did not visibly break navigation, embeds, or layouts; use curl, developer tools, or a header-focused scanner to verify the HTTP policies themselves.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Frequently Asked Questions

Should security headers be identical on every response?

No. A document, static asset, redirect, error page, and API may be generated by different layers. They should each receive the policies appropriate to their behavior, and every important path should be tested.

Can CSP replace input validation and output encoding?

No. CSP is a browser-side mitigation and resource control. It does not remove the need for secure coding, validation, authentication controls, dependency maintenance, and vulnerability testing.

Is a security-header score a compliance certification?

No. A score reflects the scanner’s rules and the responses it examined. It is not proof of compliance or of an absence of exploitable vulnerabilities.

Quick Recap

SaleBestseller No. 1
The Web Application Hacker's Handbook: Finding and Exploiting Security Flaws
The Web Application Hacker's Handbook: Finding and Exploiting Security Flaws
Comes with secure packaging; It can be a gift item; Easy to read text
$26.79
SaleBestseller No. 4
Bug Bounty Bootcamp: The Guide to Finding and Reporting Web Vulnerabilities
Bug Bounty Bootcamp: The Guide to Finding and Reporting Web Vulnerabilities
Bug Bounty Bootcamp: The Guide to Finding and Reporting Web Vulnerabilities; No Starch Press
$44.09

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.