Skip to content

HTTPS & Security Headers Test

Short answer

Check HTTPS, the HTTP-to-HTTPS redirect, mixed content, HSTS and the security and indexing headers your page sends.

What it does not do: It does not inspect the TLS certificate or its expiry date (the uptime check does), and it checks the headers of the one URL you enter.

Free · No signup · Fetched by our server
We fetch the URL on our server to run the check. Results aren't saved.

What It Does

Tests a site's HTTPS setup and the response headers that protect it. The HTTPS part checks that the page loads over HTTPS, that plain HTTP redirects to it permanently, that the secure page loads nothing over plain HTTP and that HSTS is set with a long enough max-age. The headers part checks X-Content-Type-Options, Content-Security-Policy, clickjacking protection, whether the server reveals its technology and whether an X-Robots-Tag header keeps the page out of search results.

Why It Matters

HTTPS has been a lightweight Google ranking signal since 2014, and browsers mark plain-HTTP pages as not secure. A temporary redirect, a missing HSTS header or a stray `noindex` header is easy to miss, because the page still looks fine in a browser.

How It Works

  1. Enter a page URL

  2. We request the HTTPS page and the plain-HTTP version of the same address

  3. Check the redirect, HSTS and mixed content, then read the response headers

  4. Return a result for each part, with what to fix

Sample input + output

INPUT
url: https://rankproof.eu
OUTPUT
HTTPS & redirects
  site loads over HTTPS                     OK
  HTTP → HTTPS redirect: 301                OK
  mixed content on the secure page: 0       OK
  HSTS max-age: 365 days                    OK

Security & indexing headers
  X-Content-Type-Options set                OK
  Content-Security-Policy set               OK
  clickjacking protection                   OK
  server technology hidden                  OK
  page is indexable                         OK

2 of 2 areas look good

How to read the result

Two parts
The report has an HTTPS and redirects part and a security and indexing headers part. Each has its own score, and the summary turns green only when both do, so perfect headers cannot hide a missing redirect.
Site loads over HTTPS
The address you entered answered over HTTPS. If you enter an http:// address this check fails, so enter the https:// address you want visitors to use.
HTTP → HTTPS redirect (301 in the sample)
We request the plain http:// version of the same address without following redirects. A 301 or 308 to an https:// address passes; a temporary 302 or 307 costs points, because search engines may keep showing the http:// address. If plain HTTP does not answer at all, that is not counted against you.
Mixed content (0)
Images, scripts, stylesheets, frames and other resources that the secure page loads over plain http://. Browsers block insecure scripts and frames and block or upgrade insecure media, so each one is either broken or a warning in the address bar.
HSTS max-age (365 days)
How long browsers are told to use only HTTPS for the site. A year or more passes; a shorter value or no header at all gets a warning. includeSubDomains and preload are not scored.
Security headers
X-Content-Type-Options stops browsers guessing file types; Content-Security-Policy limits where scripts may load from; X-Frame-Options or the frame-ancestors directive stops other sites framing your page (clickjacking). "Server technology hidden" means no X-Powered-By header names your software.
Page is indexable
An X-Robots-Tag header with noindex keeps the page out of search results without appearing anywhere in the HTML. It is the one header problem that turns this part red on its own.

Who Uses This

  • DevOps Engineer

    Run it after a server or CDN change to confirm the redirect, HSTS and security headers survived.

  • Security Auditor

    Review each production domain for mixed content, weak HSTS and missing security headers.

  • SEO Specialist

    Before a migration goes live, confirm HTTP redirects permanently and no header blocks indexing.

Common problems and how to fix them

  1. HTTP does not redirect, or redirects with 302

    Redirect every plain-HTTP request to the same path on HTTPS with a 301, in the web server or CDN rather than in page code, so images and files are covered too.

    # nginx
    server {
      listen 80;
      server_name example.com www.example.com;
      return 301 https://example.com$request_uri;
    }
  2. Mixed content on the secure page

    Change http:// resource addresses to https:// or, for your own files, to relative paths. If a third party has no HTTPS version, host the file yourself or drop it. The upgrade-insecure-requests directive can upgrade the rest while you work through them.

    Content-Security-Policy: upgrade-insecure-requests
  3. No HSTS, or a short max-age

    Add Strict-Transport-Security once every page works over HTTPS, and raise max-age to at least a year (31536000 seconds). Add includeSubDomains only when every subdomain has HTTPS, and preload last — preload lists are slow to leave.

    Strict-Transport-Security: max-age=31536000; includeSubDomains
  4. Security headers are missing

    Send X-Content-Type-Options: nosniff on every response. Against clickjacking, frame-ancestors in Content-Security-Policy is the current standard and X-Frame-Options covers older browsers. A full script policy takes testing, so start with these two and build it up.

    X-Content-Type-Options: nosniff
    Content-Security-Policy: frame-ancestors 'self'
    X-Frame-Options: SAMEORIGIN
  5. A noindex header you did not set

    Look for X-Robots-Tag in the server, CDN or framework settings; settings copied from a staging site are one way it happens. Remove it from pages that should be found, then request indexing for the page in Search Console.

  6. The headers name your server software

    Turn off X-Powered-By (and version numbers in the Server header) in your framework or server settings. It does not stop attacks, but it stops announcing which version to target.

    # php.ini
    expose_php = Off
    
    // Express (Node.js)
    app.disable('x-powered-by');

Frequently Asked Questions

Does it check the SSL/TLS certificate?
No. It checks whether the page loads over HTTPS, how HTTP redirects to it, HSTS, mixed content and response headers. It does not inspect the certificate or its expiry date.
What is HSTS?
HTTP Strict Transport Security — a header that tells browsers to use HTTPS for your domain even when someone types `http://`. Aim for a max-age of at least one year.
What is mixed content?
An HTTPS page that loads resources (images, scripts, CSS) over plain HTTP. Browsers block insecure scripts and upgrade or warn about insecure images.
Which headers are checked?
X-Content-Type-Options, Content-Security-Policy, X-Frame-Options or the CSP frame-ancestors directive, X-Powered-By and X-Robots-Tag. The report also lists the response headers the page returned.
How can a header block indexing?
An `X-Robots-Tag: noindex` header keeps a page out of search results just like a robots meta tag, but it does not appear in the page source, so it often goes unnoticed.
When should I run it?
After a migration, and after any server or CDN change.

Sources

The documentation this tool and the explanations on this page are based on.