Tools / Security & Crypto
Security Headers Checker
HSTS, CSP, X-Frame-Options and more — graded A to F
The lookup is made by our server against public DNS; only the domain/IP you enter is used.
About this tool
Fetch a URL and grade its security headers: HSTS, Content-Security-Policy, clickjacking protection, X-Content-Type-Options and Referrer-Policy. Each finding is based on the headers the server actually returned.
What this check covers
It fetches the URL from Korantix's servers and checks the security headers in the response: Strict-Transport-Security, Content-Security-Policy, X-Frame-Options, X-Content-Type-Options, Referrer-Policy and Permissions-Policy — and gives an A–F grade.
How to read the grade
The grade counts which protective headers are present and checks a few values (HSTS max-age of at least 180 days, nosniff). It does not judge how strict your CSP is — use the CSP Analyzer for that. Fix HSTS and nosniff first, they are quick; then plan a report-only CSP rollout.