Website security tool

HTTP Security Headers Checker

Inspect a focused allowlist of browser security policies and receive a simple Excellent, Good, or Weak grade.

Only public HTTP(S) destinations on ports 80 and 443 are allowed. IPMora sends one HEAD request from its deployment network. Response bodies and internal headers are not collected.

What the grade means

The grade measures presence of six recommended headers. It does not audit policy quality, application code, TLS configuration, authentication, or infrastructure security.

Common questions

Frequently asked questions

Does a high grade prove a website is secure?

No. Security headers are one defensive layer. Application vulnerabilities, authentication, dependencies, infrastructure, and operational controls still matter.

Does the checker download the page body?

No. It sends a HEAD request and returns only a small allowlist of security-related response headers.

Can the checker access private network addresses?

No. Private, loopback, link-local, reserved, and non-standard-port destinations are blocked before the connection.