HTTPS & Security Headers Test
Short answer
Check HTTPS, the HTTP-to-HTTPS redirect, mixed content, HSTS and the security and indexing headers your page sends.
What It Does
Tests a site's HTTPS setup and the response headers that protect it. The HTTPS part checks that the page loads over HTTPS, that plain HTTP redirects to it permanently, that the secure page loads nothing over plain HTTP and that HSTS is set with a long enough max-age. The headers part checks X-Content-Type-Options, Content-Security-Policy, clickjacking protection, whether the server reveals its technology and whether an X-Robots-Tag header keeps the page out of search results.
Why It Matters
HTTPS has been a lightweight Google ranking signal since 2014, and browsers mark plain-HTTP pages as not secure. A temporary redirect, a missing HSTS header or a stray `noindex` header is easy to miss, because the page still looks fine in a browser.
How It Works
-
Enter a page URL
-
We request the HTTPS page and the plain-HTTP version of the same address
-
Check the redirect, HSTS and mixed content, then read the response headers
-
Return a result for each part, with what to fix
Sample input + output
url: https://rankproof.eu
HTTPS & redirects site loads over HTTPS OK HTTP → HTTPS redirect: 301 OK mixed content on the secure page: 0 OK HSTS max-age: 730 days OK Security & indexing headers X-Content-Type-Options set OK Content-Security-Policy set OK clickjacking protection OK server technology hidden OK page is indexable OK 2 of 2 areas look good
Who Uses This
-
DevOps Engineer
Run it after a server or CDN change to confirm the redirect, HSTS and security headers survived.
-
Security Auditor
Review each production domain for mixed content, weak HSTS and missing security headers.
-
SEO Specialist
Before a migration goes live, confirm HTTP redirects permanently and no header blocks indexing.
Frequently Asked Questions
Does it check the SSL/TLS certificate?
No. It checks whether the page loads over HTTPS, how HTTP redirects to it, HSTS, mixed content and response headers. It does not inspect the certificate or its expiry date.
What is HSTS?
HTTP Strict Transport Security — a header that tells browsers to use HTTPS for your domain even when someone types `http://`. Aim for a max-age of at least one year.
What is mixed content?
An HTTPS page that loads resources (images, scripts, CSS) over plain HTTP. Browsers block insecure scripts and upgrade or warn about insecure images.
Which headers are checked?
X-Content-Type-Options, Content-Security-Policy, X-Frame-Options or the CSP frame-ancestors directive, X-Powered-By and X-Robots-Tag. The report also lists the response headers the page returned.
How can a header block indexing?
An `X-Robots-Tag: noindex` header keeps a page out of search results just like a robots meta tag, but it does not appear in the page source, so it often goes unnoticed.
When should I run it?
After a migration, and after any server or CDN change.