HTTP security headers check

Enter a public URL and iseeu.cc requests it from Cloudflare's network, follows any redirects, lists every response header and grades the security-related ones from A+ to F.

iseeu.cc's server requests this URL from Cloudflare's network. Ports 80 and 443 only, public hosts only, 10 checks a minute; the URL is not stored.

What it does

Response headers tell a browser how to treat a page: whether to insist on HTTPS, which scripts may run, who may frame it. This check requests your URL from iseeu.cc's server on Cloudflare's network (HEAD first, GET if the server refuses HEAD), discards any response body unread, and grades the security headers it gets back.

The graded checks:

  • Strict-Transport-Security (HSTS). Tells the browser to use only HTTPS for this host for max-age seconds, so later visits never send a plain-HTTP request that someone on shared Wi-Fi could hijack. A year (31536000) or more counts as good; includeSubDomains and preload are noted. Sent over plain HTTP, the header is ignored.
  • Content-Security-Policy (CSP). Lists where scripts and other resources may come from. If an attacker gets a <script> tag into a comment field, script-src 'self' stops it from running. 'unsafe-inline' or 'unsafe-eval' in script-src weakens that, since injected inline code and eval() then run anyway. frame-ancestors is checked too.
  • Clickjacking protection. A hostile page can place yours in a transparent frame over a decoy button, so the visitor's click lands on your page. X-Frame-Options: DENY or SAMEORIGIN, or CSP frame-ancestors 'none' or 'self', prevents it; either satisfies this check.
  • X-Content-Type-Options: nosniff. Makes the browser trust the declared Content-Type, so an uploaded text file containing JavaScript, served as text/plain, cannot be run through a script tag.
  • Referrer-Policy. With strict-origin-when-cross-origin, a page at /reset?token=abc123 tells third-party sites only its scheme and host in the Referer header, not the token.
  • Permissions-Policy. Switches off unused browser features for the page and everything it embeds. With camera=(), microphone=(), geolocation=(), a compromised ad frame or script cannot even ask for them.
  • Cross-Origin-Opener-Policy (COOP). same-origin gives your page its own browsing context group, so a window from another site that opened it, or that it opened, loses its reference and cannot navigate or probe it.

Reported but not graded: Server and X-Powered-By values like Apache/2.4.41 (Ubuntu) or PHP/7.4.3, which make matching a site to known vulnerabilities quicker, and the flags on each Set-Cookie: Secure (HTTPS only), HttpOnly (hidden from JavaScript) and SameSite (limits sending on cross-site requests).

The grade is a heuristic summary, not a security audit. Headers are one layer; they cannot fix an SQL injection or an unpatched CMS.

How to use it

  1. Enter a full public URL beginning with http:// or https://.
  2. Run the check. It gives up after 5 seconds.
  3. Read the redirect chain. Up to 5 redirects are followed, and each hop shows its status code and Location.
  4. Read the final status code, the grade and the list of response headers.

Only ports 80 and 443 are allowed. Private, loopback, link-local, carrier-grade NAT and other reserved addresses are refused, as are localhost and names under .local or .internal. Each IP address gets 10 checks a minute. The URL is not stored or logged.

The target sees a request from Cloudflare rather than from you, so a bot challenge, a country-based redirect or a server that treats HEAD differently from GET can change the result.

Use cases

  • After a deploy. Confirm a proxy or CDN change did not drop headers, such as HSTS vanishing after a load balancer swap.
  • Redirect hygiene. Check that http:// reaches https:// in one hop and that the apex and www hosts settle on one address.
  • Vendor review. Before embedding a vendor's login or payment page, see whether it allows framing at all.
  • Version leaks. Spot a Server or X-Powered-By header that names an exact version.
  • Cookie review. Make sure session cookies carry Secure, HttpOnly and SameSite before an auditor flags them.
  • CSP rollout. After leaving report-only mode, confirm the enforcing policy is live and free of 'unsafe-inline'.

A sensible starting set

A reasonable start for a site that serves its own scripts and styles:

Strict-Transport-Security: max-age=31536000; includeSubDomains
Content-Security-Policy: default-src 'self'; object-src 'none'; base-uri 'self'; frame-ancestors 'none'
X-Frame-Options: DENY
X-Content-Type-Options: nosniff
Referrer-Policy: strict-origin-when-cross-origin
Permissions-Policy: camera=(), microphone=(), geolocation=()
Cross-Origin-Opener-Policy: same-origin

X-Frame-Options repeats frame-ancestors for older browsers. This CSP blocks inline scripts, inline event handlers such as onclick, and inline styles, so test it before enforcing. If your own pages frame the site, use 'self' and SAMEORIGIN instead.

Roll out CSP in report-only mode

Send the policy as Content-Security-Policy-Report-Only and the browser blocks nothing; it logs violations to the console and to a reporting endpoint you configure. Run it through normal traffic, fix what shows up, then rename the header. You can also enforce a loose policy and trial a stricter one alongside. A report-only header on its own protects nobody.

HSTS preload is a commitment

Adding preload and submitting the domain puts it on a list built into Chrome and also used by Firefox, Safari and Edge, so browsers skip plain HTTP even on the first visit. The list requires includeSubDomains and a max-age of at least a year, so every subdomain, down to a forgotten intranet host or a printer's admin page, must serve valid HTTPS. Removal is slow, because it only reaches people as they update their browsers. Start with a max-age such as 300, raise it once nothing breaks, and preload last.

Skip X-XSS-Protection

The browser XSS filters this header controlled are gone: Chrome removed its XSS Auditor in 2019, Edge retired its filter, Firefox never had one, and the filters could be abused to switch off chosen scripts. Send X-XSS-Protection: 0 or nothing, and rely on CSP.

Checking with curl

curl -sI https://iseeu.cc/
curl -sIL http://iseeu.cc/
curl -s -D - -o /dev/null https://iseeu.cc/

The first prints the headers of a single HEAD response, including a redirect's own headers, which the hop list here leaves out. The second follows redirects and prints each response. The third sends GET and discards the body, for servers that treat HEAD differently. Add | grep -i strict-transport to isolate one header; names are case-insensitive, and HTTP/2 sends them in lowercase.

Frequently asked questions

Does an A+ mean my site is secure?

No. The grade summarizes a handful of response headers that make certain browser-side attacks harder. It says nothing about patching, authentication, access control, injection bugs or how secrets are stored. A site can score A+ and still leak data through a broken API, while a site with a lower grade can be well run. Treat it as a quick look at one layer, not an audit.

Why do I see different headers here than in my browser?

The request comes from Cloudflare's network, not from your device, and it is a HEAD request unless the server refuses HEAD. Many sites vary their response by country, by apparent bot status or by request method. A bot challenge, a geographic redirect or a framework that handles HEAD separately will each produce different headers. Run curl from your own machine to compare.

Can I check a server on my home or office network?

No. The checker connects only on ports 80 and 443 and refuses private, loopback, link-local and carrier-grade NAT addresses, other reserved ranges, and names such as localhost or ones ending in .local or .internal. That keeps it from being used to reach machines behind someone else's firewall. For an internal host, run curl -I from a machine on that network.

Is the URL I check recorded anywhere?

The URL is not stored or logged. iseeu.cc keeps no request logs and no database of visitors, and it sets no cookies. The site you check does receive a request, but that request arrives from Cloudflare's network rather than from your own IP address.

Will security settings in an HTML meta tag show up?

No. The checker reads response headers only and discards the body unread, so a policy in a meta http-equiv tag is never seen. Browsers limit meta tags too: a CSP delivered that way ignores frame-ancestors and cannot run in report-only mode, and HSTS and X-Frame-Options are ignored in meta tags entirely. Real HTTP headers are the dependable place for all of these.

What happens with long redirect chains or slow servers?

The checker follows up to 5 redirects, showing the status code and Location of each hop, and gives up after 5 seconds. A chain that needs more hops than that usually points to a misconfiguration, such as http and https or apex and www hosts sending visitors back and forth. Every extra hop also costs real visitors a round trip before the page starts to load.

The grade looks only at response headers on one request from one location. Treat it as a pointer for further work rather than a verdict on a site's overall security.