This tool checks HTTP security headers for any domain. It evaluates 10 security headers recommended for production websites:
Each header present earns points toward a total score of 100.
Enter a domain to check its security headers:
There is also an API that returns the same results in JSON format, its endpoint is: /api/lookup?url=example.com
You can find the OpenAPI specification and Swagger UI at /api-docs/ui/