d4 · tools · headers
Enter a site and our server fetches just its response headers, then grades the security story they tell: HSTS, CSP, frame protection, content-type handling and more, each explained in plain English. Redirects are followed and shown, so you see what a browser really ends up with.
Scoring is d4's own scheme, tuned to what actually mitigates attacks: an enforced CSP and HSTS carry the most weight, then content-type and framing protection, then hygiene like referrer policy and version disclosure. Plain-HTTP sites cannot score above a D. The tool only ever connects to publicly routable addresses, follows at most five redirects, fetches headers rather than pages, and is rate limited. Lookups are not logged.