Free tool

Security headers generator

Pick where your site runs, tick the protections you want and get ready-to-paste config lines. CSP starts in report-only mode so nothing breaks.

  • Free
  • No sign-up
  • Runs in your browser
1Server
2Basic headers
3Content-Security-Policy

Questions and answers

Which header should I start with?

The three safe ones: X-Content-Type-Options, X-Frame-Options and Referrer-Policy. They can hardly break anything. Then add HSTS, and CSP last.

Why is HSTS risky?

The browser remembers the rule for max-age and refuses to open the site over http. A subdomain still without HTTPS becomes unreachable. Enable it once HTTPS works everywhere.

What is CSP and why report-only?

CSP limits where the site may load scripts from. A policy that is too strict breaks analytics and widgets. In report-only mode the browser just logs what it would block and you extend the host list.

Why unsafe-inline for styles?

Many sites and CMSs use inline styles. We do not allow unsafe-inline for scripts, where the real danger is. Styles can move to nonces later.

How do I hide the server version?

nginx needs server_tokens off, Apache ServerTokens Prod, Next.js poweredByHeader: false. All of that is already in the result.

How do I check the headers work?

Run a site check in Awe Check: the HSTS, basic headers and CSP items show what is visible from outside.

Check the headers are visible from outside

In a minute Awe Check tests HTTPS, headers, cookies, exposed service files and laws.

Check a site for free