The lookup is made by our server against public DNS; only the domain/IP you enter is used.

About this tool

Fetch a URL and grade its security headers: HSTS, Content-Security-Policy, clickjacking protection, X-Content-Type-Options and Referrer-Policy. Each finding is based on the headers the server actually returned.

What this check covers

It fetches the URL from Korantix's servers and checks the security headers in the response: Strict-Transport-Security, Content-Security-Policy, X-Frame-Options, X-Content-Type-Options, Referrer-Policy and Permissions-Policy — and gives an A–F grade.

How to read the grade

The grade counts which protective headers are present and checks a few values (HSTS max-age of at least 180 days, nosniff). It does not judge how strict your CSP is — use the CSP Analyzer for that. Fix HSTS and nosniff first, they are quick; then plan a report-only CSP rollout.

Related tools