What gets checked?
When you open a website, the server sends invisible extra information along with the content, called “headers”. Some of them turn on additional protection in the browser. NetScanner checks:
- Encryption: Does the website use HTTPS (the padlock in your browser)? Are visitors automatically redirected from the insecure version to the secure one?
- Security settings: Are the six most important security headers in place? Each one is explained in a single sentence.
- Cookies: Which cookies does the website set on your first visit, and are they protected?
- Redirects: Which stops does your browser pass through on the way to the website?
- Speed: How fast does the server respond?
At the end, you get a score from 0 to 100.
Why does it matter?
These security settings cost nothing, are quick to set up and prevent whole groups of attacks, such as your website being secretly embedded in someone else’s page. Many customers, insurers and government agencies now ask about them. After moving to a new web host, these settings are often lost, so check again after every major change.
For pros
We check Strict-Transport-Security, Content-Security-Policy, X-Frame-Options (or frame-ancestors), X-Content-Type-Options, Referrer-Policy and Permissions-Policy, plus the cookie attributes Secure, HttpOnly and SameSite, the complete redirect chain and exposed server versions. The weighting: HTTPS 25 points, CSP 20, HSTS 15, the others 10 each. To see which software is behind a website, use the website technology checker. For tips on a clean move, see the domain migration checklist.