SSL & Headers
Inspect TLS certificates, HSTS configuration, Content-Security-Policy and all HTTP security headers
Target URL
About SSL & Headers
Inspect any site's SSL certificate and HTTP security headers in one scan. See TLS certificate details, HSTS, Content-Security-Policy, and other protective headers so you can harden your site and catch expiring or misconfigured certificates before your users do.
- TLS certificate and expiry details
- HSTS, CSP and security header audit
- Catch misconfigurations early
Frequently asked questions
What security headers should I have?
At minimum HSTS and a Content-Security-Policy; adding X-Content-Type-Options, X-Frame-Options, and Referrer-Policy further hardens your site.
How do I know if my certificate is about to expire?
The scan shows the certificate valid-to date so you can renew before it lapses and breaks HTTPS.