Security Headers Monitoring
Ensure your HTTP security headers stay configured.
Security headers monitoring checks that critical HTTP response headers are present and configured. Missing headers are a common source of security vulnerabilities caught in penetration tests and compliance audits.
โ๏ธHow it works
Uptrue sends a HEAD request to your URL and checks for the presence of six key security headers: Strict-Transport-Security, Content-Security-Policy, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, and Permissions-Policy.
โWhat Uptrue checks
- Strict-Transport-Security (HSTS)
- Content-Security-Policy (CSP)
- X-Frame-Options
- X-Content-Type-Options
- Referrer-Policy
- Permissions-Policy
โ Alert conditions
- One or more required security headers are missing
- No security headers found (critical)
Security headers prevent clickjacking, XSS, MIME sniffing, and data leakage. CDN configuration changes, framework updates, or reverse proxy changes can strip them silently.
?Frequently asked questions
Ready to set up Security Headers Monitoring?
Join teams who monitor their infrastructure with Uptrue. Free plan, no credit card required. Want to spot-check first? Run our free security headers checker.
Start Monitoring Free