HTTPS & Security Headers Test
Short answer
Check HTTPS, the HTTP-to-HTTPS redirect, mixed content, HSTS and the security and indexing headers your page sends.
What it does not do: It does not inspect the TLS certificate or its expiry date (the uptime check does), and it checks the headers of the one URL you enter.
What It Does
Tests a site's HTTPS setup and the response headers that protect it. The HTTPS part checks that the page loads over HTTPS, that plain HTTP redirects to it permanently, that the secure page loads nothing over plain HTTP and that HSTS is set with a long enough max-age. The headers part checks X-Content-Type-Options, Content-Security-Policy, clickjacking protection, whether the server reveals its technology and whether an X-Robots-Tag header keeps the page out of search results.
Why It Matters
HTTPS has been a lightweight Google ranking signal since 2014, and browsers mark plain-HTTP pages as not secure. A temporary redirect, a missing HSTS header or a stray `noindex` header is easy to miss, because the page still looks fine in a browser.
How It Works
-
Enter a page URL
-
We request the HTTPS page and the plain-HTTP version of the same address
-
Check the redirect, HSTS and mixed content, then read the response headers
-
Return a result for each part, with what to fix
Sample input + output
url: https://rankproof.eu
HTTPS & redirects site loads over HTTPS OK HTTP → HTTPS redirect: 301 OK mixed content on the secure page: 0 OK HSTS max-age: 365 days OK Security & indexing headers X-Content-Type-Options set OK Content-Security-Policy set OK clickjacking protection OK server technology hidden OK page is indexable OK 2 of 2 areas look good
How to read the result
- Two parts
- The report has an HTTPS and redirects part and a security and indexing headers part. Each has its own score, and the summary turns green only when both do, so perfect headers cannot hide a missing redirect.
- Site loads over HTTPS
- The address you entered answered over HTTPS. If you enter an http:// address this check fails, so enter the https:// address you want visitors to use.
- HTTP → HTTPS redirect (301 in the sample)
- We request the plain http:// version of the same address without following redirects. A 301 or 308 to an https:// address passes; a temporary 302 or 307 costs points, because search engines may keep showing the http:// address. If plain HTTP does not answer at all, that is not counted against you.
- Mixed content (0)
- Images, scripts, stylesheets, frames and other resources that the secure page loads over plain http://. Browsers block insecure scripts and frames and block or upgrade insecure media, so each one is either broken or a warning in the address bar.
- HSTS max-age (365 days)
- How long browsers are told to use only HTTPS for the site. A year or more passes; a shorter value or no header at all gets a warning. includeSubDomains and preload are not scored.
- Security headers
- X-Content-Type-Options stops browsers guessing file types; Content-Security-Policy limits where scripts may load from; X-Frame-Options or the frame-ancestors directive stops other sites framing your page (clickjacking). "Server technology hidden" means no X-Powered-By header names your software.
- Page is indexable
- An X-Robots-Tag header with noindex keeps the page out of search results without appearing anywhere in the HTML. It is the one header problem that turns this part red on its own.
Who Uses This
-
DevOps Engineer
Run it after a server or CDN change to confirm the redirect, HSTS and security headers survived.
-
Security Auditor
Review each production domain for mixed content, weak HSTS and missing security headers.
-
SEO Specialist
Before a migration goes live, confirm HTTP redirects permanently and no header blocks indexing.
Common problems and how to fix them
-
HTTP does not redirect, or redirects with 302
Redirect every plain-HTTP request to the same path on HTTPS with a 301, in the web server or CDN rather than in page code, so images and files are covered too.
# nginx server { listen 80; server_name example.com www.example.com; return 301 https://example.com$request_uri; } -
Mixed content on the secure page
Change http:// resource addresses to https:// or, for your own files, to relative paths. If a third party has no HTTPS version, host the file yourself or drop it. The upgrade-insecure-requests directive can upgrade the rest while you work through them.
Content-Security-Policy: upgrade-insecure-requests -
No HSTS, or a short max-age
Add Strict-Transport-Security once every page works over HTTPS, and raise max-age to at least a year (31536000 seconds). Add includeSubDomains only when every subdomain has HTTPS, and preload last — preload lists are slow to leave.
Strict-Transport-Security: max-age=31536000; includeSubDomains -
Security headers are missing
Send X-Content-Type-Options: nosniff on every response. Against clickjacking, frame-ancestors in Content-Security-Policy is the current standard and X-Frame-Options covers older browsers. A full script policy takes testing, so start with these two and build it up.
X-Content-Type-Options: nosniff Content-Security-Policy: frame-ancestors 'self' X-Frame-Options: SAMEORIGIN -
A noindex header you did not set
Look for X-Robots-Tag in the server, CDN or framework settings; settings copied from a staging site are one way it happens. Remove it from pages that should be found, then request indexing for the page in Search Console.
-
The headers name your server software
Turn off X-Powered-By (and version numbers in the Server header) in your framework or server settings. It does not stop attacks, but it stops announcing which version to target.
# php.ini expose_php = Off // Express (Node.js) app.disable('x-powered-by');
Frequently Asked Questions
- Does it check the SSL/TLS certificate?
- No. It checks whether the page loads over HTTPS, how HTTP redirects to it, HSTS, mixed content and response headers. It does not inspect the certificate or its expiry date.
- What is HSTS?
- HTTP Strict Transport Security — a header that tells browsers to use HTTPS for your domain even when someone types `http://`. Aim for a max-age of at least one year.
- What is mixed content?
- An HTTPS page that loads resources (images, scripts, CSS) over plain HTTP. Browsers block insecure scripts and upgrade or warn about insecure images.
- Which headers are checked?
- X-Content-Type-Options, Content-Security-Policy, X-Frame-Options or the CSP frame-ancestors directive, X-Powered-By and X-Robots-Tag. The report also lists the response headers the page returned.
- How can a header block indexing?
- An `X-Robots-Tag: noindex` header keeps a page out of search results just like a robots meta tag, but it does not appear in the page source, so it often goes unnoticed.
- When should I run it?
- After a migration, and after any server or CDN change.
Sources
The documentation this tool and the explanations on this page are based on.
- HTTPS as a ranking signal — Google Search Central Blog
- Strict-Transport-Security — MDN Web Docs
- Mixed content — MDN Web Docs
- X-Content-Type-Options header — MDN Web Docs
- Content Security Policy (CSP) — MDN Web Docs
- Content-Security-Policy: frame-ancestors directive — MDN Web Docs
- Robots Meta Tags Specifications — Google Search Central