HTTP security headers

Check whether a domain's website sets important security headers.

About HTTP security headers

What it is

HTTP security headers are instructions a web server sends along in the response to the browser. They tell the browser how to handle the page: whether it may be embedded in an iframe, whether https should always be used, and more.

Why it matters

Without security headers, your site can be vulnerable to clickjacking, mixed content and other attacks that are otherwise easy to prevent. Properly configured headers are one of the simplest and cheapest security improvements available.

Tips

Common questions

Which header is most important to start with?

HSTS is the easiest to set and provides immediate value. X-Content-Type-Options and X-Frame-Options are quick to add and require almost no adaptation.

Do security headers affect performance?

Marginally, they are added to the HTTP response header and amount to a few hundred bytes. No measurable performance impact in practice.

More lookups

MX lookup

See which servers receive mail for a domain, and which provider handles it.

SPF check

Check whether a domain has an SPF record and how strictly it rejects spoofed mail.

DMARC check

See whether a domain has DMARC and which policy it uses against spoofed mail.

DKIM check

Look for DKIM signing on a domain using the most common selectors.

DNSSEC check

See whether a domain is protected with DNSSEC, that is, whether its DNS answers are signed.

TXT lookup

List all TXT records for a domain, including SPF, verifications and more.

NS lookup

See which name servers control a domain's DNS.

Blacklist check

Check whether a domain's IP address is on blacklists such as Spamhaus, Barracuda and SpamCop.

A/AAAA lookup

See which IP addresses a domain points to, both IPv4 (A) and IPv6 (AAAA).

CNAME lookup

See whether a domain is an alias that points on to another domain.

SOA lookup

See the zone's core data: primary name server, contact and serial number.

CAA lookup

See which certificate authorities are allowed to issue certificates for the domain.

Reverse DNS (PTR)

Look up which host name a domain's IP address points back to.

MTA-STS

See whether a domain requires encrypted mail delivery via MTA-STS.

TLS-RPT

See whether a domain receives reports about failed encrypted mail delivery.

BIMI

See whether a domain publishes a logo that can be shown in the recipient's inbox.

SSL certificate

Check a domain's TLS certificate: issuer, validity and expiry.

Whois

See who owns a domain, when it was registered and when it expires.

← Back to KOLLEN
HTTP security headers: check a website's headers | LUMRA KOLLEN