HTTP Security Headers

    Fetches a URL from your browser and grades its HTTP response headers against modern best practices (HSTS, CSP, X-Frame-Options, Referrer-Policy and more).

    Tries a direct fetch first. If the target site does not send Access-Control-Allow-Origin (most large sites don't), automatically retries via the publiccorsproxy.io gateway. Results fetched via the proxy are labelled below.