Website security check
Loads your home page the way a visitor's browser does and checks the settings that block common attacks: forced HTTPS, script limits, clickjacking protection and safe cookies. Each gap comes with the exact header or DNS record to add.
What we check
HTTPS and the http:// redirect, HSTS, Content-Security-Policy, X-Frame-Options or frame-ancestors, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, cookie flags, software versions in headers, DNSSEC and CAA. We follow up to five redirects.
What we don't check
Certificate expiry and details (this check can't read them), other pages, plugins or software bugs. It finds common exposures attackers look for; it isn't a penetration test. The domain and results aren't stored or logged.