Why browser checks are limited
A web page cannot freely read another origin's response headers. The target must opt in with Access-Control-Allow-Origin, and only CORS-safelisted or explicitly exposed headers are available to JavaScript. A network error can therefore mean “the server blocked browser access,” not “the server has no security headers.”
Headers covered
- Content-Security-Policy: controls which resources a document may load and where it may send data.
- Strict-Transport-Security: tells browsers to use HTTPS for a period of time; only meaningful when delivered over HTTPS.
- X-Content-Type-Options:
nosniffreduces MIME-type confusion. - Referrer-Policy: limits how much referrer information leaves a page.
- Permissions-Policy: restricts browser features such as camera, microphone and geolocation.
- Cross-Origin-Opener-Policy and Cross-Origin-Resource-Policy: help isolate browsing contexts and control cross-origin resource use.
For authoritative results, inspect response headers at the server or CDN, test redirects and representative routes, and use a security scanner you trust. Never paste credentials or sensitive URLs into a third-party checker.