Enter your domain and abr.cloud reads the HTTP security headers your site sends — the browser-level defences against XSS, clickjacking and content sniffing — and grades them with the exact header to add for each gap.
One quick verification, no account. We store nothing unless you start monitoring.
Security headers are instructions your site sends to the browser that switch on built-in protections: Content-Security-Policy limits what can run, HSTS forces HTTPS, X-Content-Type-Options stops MIME sniffing, and more. They're free to add and close whole classes of attack — but most sites ship with several missing.
Content-Security-Policy (not just default-src *).Strict-Transport-Security (HSTS) with a long max-age.X-Content-Type-Options: nosniff and a sane Referrer-Policy.frame-ancestors (or X-Frame-Options).Yes — free with a quick CAPTCHA, no account. It only reads your public HTTP response.
CSP is the biggest lever against XSS, but HSTS and nosniff are quick wins. The check grades each so you know where to start.
CSP can, if too strict — that's why you roll it out in report-only mode first. The others are safe.
abr.cloud puts 80+ network & security tools behind one fast interface — with AI analysis and always-on monitoring.
open abr.cloud →