Free tool
Security Headers Grade
We fetch the page ourselves and check the response headers directly — no dependency on a third-party scanner.
FAQ
Which headers does this check?
Strict-Transport-Security, Content-Security-Policy, X-Content-Type-Options, X-Frame-Options (or an equivalent frame-ancestors CSP directive), Referrer-Policy, and Permissions-Policy — the six that cover the most common header-based attack classes.
Is this the same as Mozilla Observatory?
Similar idea, run independently: we fetch your page and read the headers ourselves rather than depending on a third-party scanner's uptime.
Do security headers affect SEO?
Not directly as a ranking factor, but HTTPS itself is a confirmed signal, and headers like HSTS reinforce it. Missing headers are more of a trust and security-hygiene issue — the kind of thing a technical audit flags.
More free tools
Want this on autopilot?
Run the full Omnitopical engine on your domain — one plan, $99/mo.