Scan a site
Enter any public HTTPS URL to see what security headers the server sends.
No scheme? https:// is added automatically. Private or internal hosts are rejected.
What this tool does and does not do.
Headergrade fetches the URL you type, follows up to two redirects, and returns every HTTP response header the server actually sent. For each of the seven key security headers it provides a plain-language explanation and a specific change to make. It does not crawl your site, test for vulnerabilities, or store any data. This is a diagnostic tool, not a compliance scanner — read terms for details.
Platform limit: This tool runs on Cloudflare Workers. Because Cloudflare's own network intercepts requests to sites also behind Cloudflare, the worker cannot open a direct socket to those origins. If a site behind Cloudflare returns unexpected headers (or an unreachable error), that is a platform limitation, not a result about your network or server.
Headergrade fetches the URL you type, follows up to two redirects, and returns every HTTP response header the server actually sent. For each of the seven key security headers it provides a plain-language explanation and a specific change to make. It does not crawl your site, test for vulnerabilities, or store any data. This is a diagnostic tool, not a compliance scanner — read terms for details.
Platform limit: This tool runs on Cloudflare Workers. Because Cloudflare's own network intercepts requests to sites also behind Cloudflare, the worker cannot open a direct socket to those origins. If a site behind Cloudflare returns unexpected headers (or an unreachable error), that is a platform limitation, not a result about your network or server.