Security headers

HSTS, CSP, X-Content-Type-Options and more, scored with their values checked, after following redirects.

sec.headers

What it checks

  • HSTS, CSP, X-Content-Type-Options, X-Frame-Options, Referrer-Policy and Permissions-Policy.
  • Values are scored too, not just presence, for example a short max-age or unsafe-inline.
  • Follows redirects to the final page and shows server versions leaking in the headers.

Hosting that passes every one of these checks

LimaCloud is tuned so your site and mail pass every one of these checks, and we prove it with a benchmark before and after migration.

Tool search Esc
↑ ↓ select · Enter open · Esc close