Web status · Web status & headers
Security headers: the A-F grade explained
A security headers grade (A, B, C, D, E, F) summarizes how well your site is configured to resist the most common browser-level attacks: clickjacking, XSS, mixed content, downgrade attacks. Each missing or misconfigured header costs you. The grader gives a 0–100 score and a checklist of what to add.
TL;DR
A security headers grader checks your site for HSTS, CSP, X-Frame-Options, Referrer-Policy, Permissions-Policy, and 5 others. Here is what each one does and how to fix it.
The four headers that matter most
Strict-Transport-Security (HSTS) tells browsers to use HTTPS only for the next year. Content-Security-Policy (CSP) restricts what scripts and styles the page can load. X-Frame-Options or frame-ancestors in CSP prevents the page from being embedded in an iframe. Referrer-Policy controls how much information about the previous URL is sent. Together, these four cover the most common attack vectors.
The smaller ones
X-Content-Type-Options: nosniff prevents MIME-sniffing (where a browser guesses the content type and executes it as a different type). Permissions-Policy disables browser features by default (camera, microphone, geolocation). Cross-Origin-Opener-Policy and Cross-Origin-Embedder-Policy are newer headers for isolation. Cross-Origin-Resource-Policy controls which sites can load your resources.
How to get from F to A
Most sites can reach A in 30 minutes by adding the four headers above. HSTS is one line: Strict-Transport-Security: max-age=31536000; includeSubDomains; preload. CSP starts permissive (default-src 'self') and tightens over time. X-Frame-Options is one line: DENY (or SAMEORIGIN if you use iframes). The grader tells you which ones are missing and gives you the exact header to add.
Common gotchas
HSTS only works over HTTPS — adding it on an HTTP site has no effect. CSP conflicts with inline scripts (you need nonces or hashes, or you can use strict-dynamic). Permissions-Policy has a default-allow and default-deny mode — choose one. X-Frame-Options is being replaced by frame-ancestors in CSP, but still works for legacy browsers. The grader scores each header individually, so a partial config still gets partial credit.
Try it →
Run the Security headers tool on sitetrace.it.com — paste a value and get an instant answer.
Open Security headers