Check HTTP security headers, email security records and your Mozilla Observatory grade in seconds
This page runs three instant website security checks against any domain or URL you enter. The security headers checker reviews browser protections such as Content Security Policy, HSTS and clickjacking controls. The email security checker reads public DNS records to verify whether SPF, DKIM and DMARC are correctly configured. The Mozilla Observatory tab gives your site an independent letter grade based on Mozilla's wider scoring model.
No account is needed and nothing is stored. Enter a domain or URL and results appear within 30 seconds.
HTTP security headers are instructions your web server sends to browsers when a page is loaded. They are invisible to visitors but control how browsers handle your content.
Content-Security-Policy (CSP) restricts which scripts, styles and resources a browser is allowed to load, reducing the risk of cross-site scripting (XSS) attacks. It is one of the most impactful headers to get right and also one of the most complex to configure without breaking functionality.
X-Frame-Options prevents your pages from being embedded in iframes on other sites, which is a common technique in clickjacking attacks. Strict-Transport-Security (HSTS) forces browsers to connect over HTTPS even if a user types a plain HTTP address. X-Content-Type-Options stops browsers from guessing at file types, closing off a class of injection vulnerabilities.
Missing headers rarely cause visible problems until something goes wrong. A clean set of headers is a baseline expectation for any business handling customer data or running transactions online.
SPF (Sender Policy Framework) is a DNS record that lists the mail servers authorised to send email on behalf of your domain. If it is missing or misconfigured, receiving mail servers may reject your messages or allow spoofed versions through.
DKIM (DomainKeys Identified Mail) adds a cryptographic signature to outgoing email so recipients can verify the message has not been altered in transit. Without it, your emails are easier to tamper with and more likely to be marked as spam.
DMARC (Domain-based Message Authentication, Reporting and Conformance) ties SPF and DKIM together and tells receiving servers what to do when a check fails -- whether to quarantine the message, reject it or do nothing. A policy of p=none means you are monitoring only; p=quarantine or p=reject gives active protection.
If any of these records are missing or set to a permissive policy, your domain can be used to send phishing emails that appear to come from your business. See our email security service for help getting this right.
Mozilla Observatory is a recognised website security scanner that grades browser-facing protections such as HTTP headers, TLS configuration, cookies and referrer policy.
Use it alongside the headers and email tabs to understand your public security posture.
Enter your URL below and wait a few seconds to get started.
Mozilla Observatory grades websites from F to A+ based on a weighted set of security checks. It covers much of the same ground as the headers scanner but applies Mozilla's own scoring model and flags additional issues such as subresource integrity, cookie security attributes and referrer policy.
A score below C suggests meaningful gaps in your web security posture. An A or A+ does not mean your site is unbreachable, but it does mean the most commonly exploited browser-level weaknesses have been addressed. If your score is lower than expected, use the Full Report link after your scan to see exactly which tests failed and why.
Mozilla Observatory checks public browser and server configuration. It does not test login logic, user permissions, API authorisation, payment flows, file uploads or whether one customer can access another customer's data. If your site has accounts, portals, bookings or payments, see our web application penetration testing service. If APIs connect your app, mobile backend or integrations, see our API penetration testing service.
Most of the issues these tools surface are fixable -- but they require access to your DNS provider, your web server configuration and sometimes your email platform, and they need to be done carefully to avoid breaking existing mail flow or site functionality. Getting DMARC wrong, for example, can cause legitimate email to be rejected.
If you would rather have a specialist handle it, our email security service covers SPF, DKIM and DMARC setup and ongoing monitoring, while our web application penetration testing and API penetration testing services go beyond automated checks to find vulnerabilities in logins, customer portals, booking systems, SaaS platforms and APIs. For businesses looking to meet a recognised security standard, Cyber Essentials certification addresses secure configuration across your wider environment.
Yes. No account, no email address and no payment is required. The checks run against public DNS records and your website's HTTP responses.
Any publicly accessible domain. Enter the root domain for email checks (e.g. yourbusiness.co.uk) and the full URL for header and Observatory scans (e.g. https://yourbusiness.co.uk).
No. The scans read publicly available information only -- DNS records and HTTP response headers. No login credentials are used and no content is written to your server.
SPF records can fail for several reasons beyond simply being absent. Common issues include too many DNS lookups (the limit is ten), outdated entries for mail services you no longer use, or a missing ~all or -all qualifier at the end of the record.
After any change to your DNS settings, mail platform or web server configuration. As a general baseline, running checks quarterly is a reasonable habit for most SMEs.
Mozilla Observatory is a public website security scanner that grades a site based on browser-facing security configuration, including HTTP headers, TLS settings, cookies, referrer policy and related best practices.
No. Mozilla Observatory checks visible browser and server configuration. A penetration test goes further by manually testing login logic, access controls, API authorisation, file uploads, payment flows and whether customer data can be exposed.
An A or A+ usually means the main browser-level protections are in place. A lower grade suggests configuration gaps worth fixing, but a high score does not prove that the wider application or API is secure.
Yes. We can help fix failed security header, HTTPS and email authentication checks. If the website includes logins, customer data, payments or APIs, we can also provide web application penetration testing and API penetration testing.
Found gaps in your setup? If you need help fixing headers, SPF, DKIM, DMARC or Mozilla Observatory findings, book a free review. If your website has logins, customer data, bookings, payments or APIs, start with our web app penetration testing or API penetration testing service.
Also free: our Password Strength & Breach Checker, Phishing Awareness Quiz and Cyber Essentials Readiness Self-Assessment -- no signup required for any of them.