Security Headers Builder and Checker

Inspect pasted HTTP headers by group, check security fields or draft a non-CSP header block.

Inputs stay on your device No sign-up Free to use
How this works

The tool runs in this browser. Your file or text is not uploaded to UseFreeTools. Check this tool's limits for anything it may save on your device.

Privacy details

Build or check headers controls

Showing an example. Edit to see your own.

Used by Check and Inspect. Inspect groups caching, content, security and cookies; credential values are hidden in its report. The tool does not fetch a URL.

One Name: value per line, for anything the choices above do not cover. Content-Security-Policy is refused here because the CSP Generator page builds it.

What to do

Check reads a response header block you paste. Build writes one from the choices below.

Browsers remember HSTS for this long. Start with a short value only if you are sure every subdomain already serves https.

Preload puts the host in browser lists. It needs includeSubDomains and a long max-age, and removal is slow.

0 turns off the legacy XSS filter, which current guidance recommends.

Processed in your browser. Your inputs stay on this device.

How to use Security Headers Builder and Checker

  1. Choose Build a header block and set the values, starting with the HSTS max-age, or choose Check pasted headers and paste a response header block.
  2. For a check, paste the output of a header request such as curl -I; a status line and blank lines are skipped.
  3. The rows and notes update as you change the fields.
  4. Read the rows and the notes, apply the change on the host, then request the headers again to confirm what the server now sends.

Example: Security Headers Builder and Checker

Draft the default block, then check a pasted response that is close to it.

You add
Build mode with an HSTS max-age of 1 year and includeSubDomains on, X-Frame-Options SAMEORIGIN, nosniff on, Referrer-Policy strict-origin-when-cross-origin, location, camera and microphone turned off in Permissions-Policy, Cross-Origin-Opener-Policy same-origin, Cross-Origin-Resource-Policy same-origin and X-XSS-Protection 0.
You get
Eight headers in this order: Strict-Transport-Security with max-age=31536000; includeSubDomains, X-Frame-Options SAMEORIGIN, X-Content-Type-Options nosniff, Referrer-Policy strict-origin-when-cross-origin, Permissions-Policy with the three features off, Cross-Origin-Opener-Policy same-origin, Cross-Origin-Resource-Policy same-origin and X-XSS-Protection 0.

Options

Response headers to check
The check reads a header block copied from a response. A first line such as HTTP/2 200 and any blank line is skipped, so output pasted straight from a header request is fine.
Extra headers
One Name: value pair per line for anything the choices do not cover. Content-Security-Policy is refused here on purpose, because the CSP Generator page builds a policy with its own rules and checks.
General header inspection
Choose Inspect any pasted headers to group caching, content, security, cookies and routing fields. Duplicate lines stay separate. Cookie and credential values are hidden in this report. A request target is also hidden; no URL is fetched.

Supported inputs and limits

The build writes eight headers, plus any extra lines you add, and it refuses Content-Security-Policy so the two tools do not disagree. The check reads up to 100,000 characters and 200 headers and marks each one pass, to review or missing. It reads text you paste, so it cannot see what the live host returns: a proxy, a CDN or the application itself may add, rewrite or strip headers on the way out. HSTS is remembered by browsers rather than applied per request, so it takes effect over time and is awkward to withdraw; a short max-age on a live host can leave a visitor's browser remembering a rule you wanted to test. Confirm any change by requesting the headers again after you apply it. General inspection stops at the first blank line after headers, rejects folded/control-bearing lines and refuses more than 200 fields or a value longer than 4,096 characters. Unknown fields are listed without a guessed explanation.

Where your input is processed

This tool processes your input in this browser. Your text and files are not uploaded to UseFreeTools. Check this tool's limits for anything it may save on your device.

What each header is doing

The headers here each close a specific door. HSTS tells a browser to keep using https for a host, nosniff stops it from guessing a file type, X-Frame-Options and the frame-ancestors rule decide who may put the page inside a frame, Referrer-Policy trims the address sent to other sites, Permissions-Policy switches browser features off for the page and its frames, and the two Cross-Origin headers decide which other origins may read a response or keep a window handle. None of them are a substitute for a content policy, input validation or a patched server, and a header that breaks a real workflow is worse than one that is missing. Change one at a time, check the page afterwards, and keep a note of the value you replaced.

MDN: Strict-Transport-Security

MDN: X-Frame-Options

OWASP Secure Headers Project

Questions about Security Headers Builder and Checker

Where do I get the response headers?

Run a header request such as curl -I against the address, or open the Network panel in your browser's developer tools, select the document request and read its response headers. Copy the whole block, including the status line, because the page skips it for you.

Why is Content-Security-Policy not built here?

A policy has to allow exactly the sources your page uses, and a wrong one either breaks the page or allows more than intended. That needs its own page with its own checks, and this site has one, so this tool stays with the headers that take a single value.

Can I trust a check of pasted headers for my live site?

Only for the response you pasted. A CDN, a proxy or an application framework can add or remove headers on the way to the browser, and a cached response can come from a layer that behaves differently from the origin. Request the address you actually serve, from the same path a visitor takes, and compare more than one response when a layer sits in front.

Is HSTS safe to turn on?

Once a browser has seen a long HSTS value it will refuse plain http to that host until the period passes, and it applies to subdomains when includeSubDomains is set. Turn it on when every name it covers already serves https, keep the first value modest if you are unsure, and check the subdomains before you lengthen it.

What does to review mean?

It marks a value that is present but not the one this page expects, such as a short max-age, a legacy X-XSS-Protection value, or a name that was renamed. It is a prompt to read the value, not an automatic failure, because your hosting may have a reason for it.

Project manager: Tony Hines · Content updated 30 September 2026 · Report a problem