HTTP security headers checker
See which HTTP security headers a site sends, which are missing, and what each one protects against.
- HSTS, CSP, framing and referrer rules
- Missing headers explained
- Observed date on every result
Give it something to look up — Glee will do the digging.
How the security headers checker works
Security headers are instructions a site sends the browser: only ever connect over HTTPS (HSTS), only run scripts from these places (CSP), never show this page inside another site (framing protection), and send less of the visitor's address to other sites (Referrer-Policy). They cost nothing to send and close whole classes of attacks.
This checker requests the page and lists the security-relevant headers it returns, the ones that are missing, and what each is for. Agencies use it as a quick, repeatable audit item across client sites.
Check the address visitors actually land on: headers are set per response, so the http:// address, the bare domain and the final https:// page can all differ. A site that sends HSTS only on some pages, or a CSP in report-only mode, is reported as it is observed, with the date.
What each field means
- Present / missing
- Which headers the response carried.
Where this check stops
- Header findings are not a security certification or an exploitability assessment.
The same check, through the API
Same calculation, same answer, with a key. 5 credits per check ($0.50 per 1,000). A free account includes 1,000 credits a month.
POST /v1/web {"url":"https://acme.com"}
Host: gleanzy.com
Authorization: Bearer $GLEANZY_KEYFrequently asked
Is a missing header a vulnerability?
Not by itself. It is a missing layer of defence; whether it matters depends on the site.
Which header matters most?
For most sites, HSTS (so the browser never falls back to plain HTTP) and a Content-Security-Policy that limits where scripts can load from.