HTTP Security Headers Inspector

Review common browser security headers on a URL you control. The optional check is a direct request from your browser: there is no proxy, server-side fetch, or bypass for CORS.

Enter an HTTP or HTTPS URL. Only headers exposed by the target's CORS policy can be read.
Header review
Observed security headers
HeaderValue / findingGuidance
Embed this tool on your website / blog No code required · Copy and paste
HTML Embed Code (iframe):
<iframe src="https://lucentool.com/security-headers-checker" width="100%" height="650" style="border:1px solid #e5e0d8;border-radius:12px;max-width:850px;width:100%;" frameborder="0"></iframe>
<div style="font-size:12px;color:#78716c;margin-top:6px;font-family:sans-serif;">Powered by <a href="https://lucentool.com/security-headers-checker" target="_blank" style="color:#c85a32;text-decoration:none;">Lucentool - HTTP Security Headers Inspector</a></div>

Why browser checks are limited

A web page cannot freely read another origin's response headers. The target must opt in with Access-Control-Allow-Origin, and only CORS-safelisted or explicitly exposed headers are available to JavaScript. A network error can therefore mean “the server blocked browser access,” not “the server has no security headers.”

Headers covered

For authoritative results, inspect response headers at the server or CDN, test redirects and representative routes, and use a security scanner you trust. Never paste credentials or sensitive URLs into a third-party checker.