Free tool
Security headers generator
Pick where your site runs, tick the protections you want and get ready-to-paste config lines. CSP starts in report-only mode so nothing breaks.
- Free
- No sign-up
- Runs in your browser

Questions and answers
Which header should I start with?
The three safe ones: X-Content-Type-Options, X-Frame-Options and Referrer-Policy. They can hardly break anything. Then add HSTS, and CSP last.
Why is HSTS risky?
The browser remembers the rule for max-age and refuses to open the site over http. A subdomain still without HTTPS becomes unreachable. Enable it once HTTPS works everywhere.
What is CSP and why report-only?
CSP limits where the site may load scripts from. A policy that is too strict breaks analytics and widgets. In report-only mode the browser just logs what it would block and you extend the host list.
Why unsafe-inline for styles?
Many sites and CMSs use inline styles. We do not allow unsafe-inline for scripts, where the real danger is. Styles can move to nonces later.
How do I hide the server version?
nginx needs server_tokens off, Apache ServerTokens Prod, Next.js poweredByHeader: false. All of that is already in the result.
How do I check the headers work?
Run a site check in Awe Check: the HSTS, basic headers and CSP items show what is visible from outside.
Keep reading
Check the headers are visible from outside
In a minute Awe Check tests HTTPS, headers, cookies, exposed service files and laws.