If you've used the popular Security Headers extension (or securityheaders.com), you already know the value: open a page, get a grade, see which HTTP response headers are missing. It's a great, focused tool — and if all you ever need is a header check, it does that job well.
But here's the catch most people miss: your HTTP headers are only one slice of what an attacker sees. A site can score an A on headers and still be wide open somewhere else. So if you're looking for an alternative, the real question isn't "which tool grades headers best" — it's "what else am I not checking?"
The five things a header-only checker misses
Headers are one of six layers worth grading. The other five:
- HTTPS & HSTS configuration. Not just "is there a padlock," but whether HTTP properly redirects to HTTPS and whether HSTS is set so browsers refuse to downgrade. A missing redirect is a real man-in-the-middle opening.
- Cookie flags. A session cookie without
HttpOnlycan be read by any injected JavaScript; withoutSecureit can leak over HTTP; withoutSameSiteit's exposed to CSRF. Header checkers don't inspect your cookies. - Email spoofing (SPF & DMARC). If your domain's DNS is missing SPF and DMARC, anyone can send email that looks like it came from you — a classic phishing vector that has nothing to do with your web headers.
- Outdated JavaScript libraries. A front-end still shipping jQuery 1.x or an old framework with known CVEs is exploitable no matter how perfect your CSP is.
- Exposed subdomains. Public certificate logs reveal the subdomains you've issued certs for — and often that list includes
admin.,dev.,staging.orjenkins.systems you never meant to expose. Attackers check these first.
The alternative: grade all six in one click
This is exactly the gap SurfaceWatch was built for. It's a free Chrome extension that checks the same headers a header-only tool does — plus all five layers above — and rolls them into a single A–F grade for the page you're on. Every issue is listed by severity, and every fixable one comes with a copy-paste fix for nginx, Apache, Netlify, Vercel, Express or your DNS.
So instead of "your headers are a B," you get "your site is a 44/100, here's the ranked list, here's the exact config to fix each one."
When each one is the right choice
- Just want a quick header grade? A header-only checker is fast and perfect for that.
- Want to know your real exposure — or you're checking a client's site? You want the whole surface: headers + HTTPS + cookies + SPF/DMARC + libraries + subdomains, in one grade. That's the SurfaceWatch case.
Both are free, and the checks are passive (they only read what's already public), so you can run either on sites you don't own. If you've outgrown "headers only," that's your sign to grade the rest.
One honest caveat on the fixes: everything except Content-Security-Policy is safe to paste as-is. For CSP, ship it in report-only mode first and tune it — a strict policy can break your own scripts. A good checker flags this for you.