Skip to content

HTTPS & Security Headers Test

Short answer

Check HTTPS, the HTTP-to-HTTPS redirect, mixed content, HSTS and the security and indexing headers your page sends.

Free · No signup · Fetched by our server
We fetch the URL on our server to run the check. Results aren't saved.

What It Does

Tests a site's HTTPS setup and the response headers that protect it. The HTTPS part checks that the page loads over HTTPS, that plain HTTP redirects to it permanently, that the secure page loads nothing over plain HTTP and that HSTS is set with a long enough max-age. The headers part checks X-Content-Type-Options, Content-Security-Policy, clickjacking protection, whether the server reveals its technology and whether an X-Robots-Tag header keeps the page out of search results.

Why It Matters

HTTPS has been a lightweight Google ranking signal since 2014, and browsers mark plain-HTTP pages as not secure. A temporary redirect, a missing HSTS header or a stray `noindex` header is easy to miss, because the page still looks fine in a browser.

How It Works

  1. Enter a page URL

  2. We request the HTTPS page and the plain-HTTP version of the same address

  3. Check the redirect, HSTS and mixed content, then read the response headers

  4. Return a result for each part, with what to fix

Sample input + output

INPUT
url: https://rankproof.eu
OUTPUT
HTTPS & redirects
  site loads over HTTPS                    OK
  HTTP → HTTPS redirect: 301               OK
  mixed content on the secure page: 0      OK
  HSTS max-age: 730 days                   OK

Security & indexing headers
  X-Content-Type-Options set               OK
  Content-Security-Policy set              OK
  clickjacking protection                  OK
  server technology hidden                 OK
  page is indexable                        OK

2 of 2 areas look good

Who Uses This

  • DevOps Engineer

    Run it after a server or CDN change to confirm the redirect, HSTS and security headers survived.

  • Security Auditor

    Review each production domain for mixed content, weak HSTS and missing security headers.

  • SEO Specialist

    Before a migration goes live, confirm HTTP redirects permanently and no header blocks indexing.

Frequently Asked Questions

Does it check the SSL/TLS certificate?

No. It checks whether the page loads over HTTPS, how HTTP redirects to it, HSTS, mixed content and response headers. It does not inspect the certificate or its expiry date.

What is HSTS?

HTTP Strict Transport Security — a header that tells browsers to use HTTPS for your domain even when someone types `http://`. Aim for a max-age of at least one year.

What is mixed content?

An HTTPS page that loads resources (images, scripts, CSS) over plain HTTP. Browsers block insecure scripts and upgrade or warn about insecure images.

Which headers are checked?

X-Content-Type-Options, Content-Security-Policy, X-Frame-Options or the CSP frame-ancestors directive, X-Powered-By and X-Robots-Tag. The report also lists the response headers the page returned.

How can a header block indexing?

An `X-Robots-Tag: noindex` header keeps a page out of search results just like a robots meta tag, but it does not appear in the page source, so it often goes unnoticed.

When should I run it?

After a migration, and after any server or CDN change.