Live check
Security Headers Checker
Working tool — nothing here invents breach rates or detection timers. When you are ready, request a briefing about the 0g0 Appliance.
Request a BriefingAll free toolse.g. agency.gov.au · example.com · https://example.com (protocol is optional)
HSTS
Forces HTTPS connections and prevents SSL-stripping attacks.
CSP
Prevents XSS by controlling which scripts and resources can run.
X-Frame-Options
Blocks clickjacking by preventing iframe embedding.
X-Content-Type
Prevents MIME sniffing attacks from malicious uploads.
Referrer-Policy
Controls information shared via the Referrer header.
Permissions-Policy
Restricts browser feature access like camera and mic.