How to use Security Headers Builder and Checker
- Choose Build a header block and set the values, starting with the HSTS max-age, or choose Check pasted headers and paste a response header block.
- For a check, paste the output of a header request such as curl -I; a status line and blank lines are skipped.
- The rows and notes update as you change the fields.
- Read the rows and the notes, apply the change on the host, then request the headers again to confirm what the server now sends.
Example: Security Headers Builder and Checker
Draft the default block, then check a pasted response that is close to it.
Options
- Response headers to check
- The check reads a header block copied from a response. A first line such as HTTP/2 200 and any blank line is skipped, so output pasted straight from a header request is fine.
- Extra headers
- One Name: value pair per line for anything the choices do not cover. Content-Security-Policy is refused here on purpose, because the CSP Generator page builds a policy with its own rules and checks.
- General header inspection
- Choose Inspect any pasted headers to group caching, content, security, cookies and routing fields. Duplicate lines stay separate. Cookie and credential values are hidden in this report. A request target is also hidden; no URL is fetched.
Supported inputs and limits
Where your input is processed
This tool processes your input in this browser. Your text and files are not uploaded to UseFreeTools. Check this tool's limits for anything it may save on your device.
What each header is doing
The headers here each close a specific door. HSTS tells a browser to keep using https for a host, nosniff stops it from guessing a file type, X-Frame-Options and the frame-ancestors rule decide who may put the page inside a frame, Referrer-Policy trims the address sent to other sites, Permissions-Policy switches browser features off for the page and its frames, and the two Cross-Origin headers decide which other origins may read a response or keep a window handle. None of them are a substitute for a content policy, input validation or a patched server, and a header that breaks a real workflow is worse than one that is missing. Change one at a time, check the page afterwards, and keep a note of the value you replaced.
Questions about Security Headers Builder and Checker
Where do I get the response headers?
Run a header request such as curl -I against the address, or open the Network panel in your browser's developer tools, select the document request and read its response headers. Copy the whole block, including the status line, because the page skips it for you.
Why is Content-Security-Policy not built here?
A policy has to allow exactly the sources your page uses, and a wrong one either breaks the page or allows more than intended. That needs its own page with its own checks, and this site has one, so this tool stays with the headers that take a single value.
Can I trust a check of pasted headers for my live site?
Only for the response you pasted. A CDN, a proxy or an application framework can add or remove headers on the way to the browser, and a cached response can come from a layer that behaves differently from the origin. Request the address you actually serve, from the same path a visitor takes, and compare more than one response when a layer sits in front.
Is HSTS safe to turn on?
Once a browser has seen a long HSTS value it will refuse plain http to that host until the period passes, and it applies to subdomains when includeSubDomains is set. Turn it on when every name it covers already serves https, keep the first value modest if you are unsure, and check the subdomains before you lengthen it.
What does to review mean?
It marks a value that is present but not the one this page expects, such as a short max-age, a legacy X-XSS-Protection value, or a name that was renamed. It is a prompt to read the value, not an automatic failure, because your hosting may have a reason for it.