H6 · Infrastructure, Bots & DNS

    Security Headers Checker — are your HTTP headers configured?

    HTTP response headers are a quiet but powerful layer — they can harden your site against attacks and control how engines index it, all before any HTML loads. This check looks at your security headers (like HSTS and Content-Security-Policy) and robots-related headers (like X-Robots-Tag). Sensible headers improve security and give you server-level control over indexing that the page markup can't.
    Updated June 2026 · Technical SEO & GEO · Part of Infrastructure, Bots & DNS

    Check your security & robots headers

    Paste a URL — GEObubbly checks your HTTP response headers for security protections and robots directives.

    ✓ Free check✓ 1 signal✓ No signup required
    In short: Sensible response headers — HSTS, CSP, X-Content-Type-Options, Referrer-Policy and X-Robots-Tag — harden your site and give server-level indexing control your HTML can't.

    What does the headers check look for?

    It inspects your HTTP response headers for both security and indexing controls. Specifically:

    • HSTS — Strict-Transport-Security forcing browsers to use HTTPS.
    • Content-Security-Policy — limiting what resources can load, reducing injection risk.
    • Other protections — headers like X-Content-Type-Options and Referrer-Policy.
    • X-Robots-Tag — server-level indexing directives, useful for non-HTML resources like PDFs.

    Sensible security and robots headers passes; some present but key ones missing is a warning; no meaningful security headers is a fail.

    How is it evaluated, and how is it scored?

    GEObubbly inspects the page's HTTP response headers for security and robots directives. It's an extended Infrastructure check that runs partially, since it reads the live response headers.

    Criteria: Pass — reasonable security headers. Warning — missing some security headers. Fail — no security headers.

    Why security and robots headers matter for SEO and GEO

    HTTP response headers are instructions the server sends with every response, before any HTML — and they do two useful jobs. On the security side, headers like Strict-Transport-Security (HSTS, which forces browsers to always use HTTPS), Content-Security-Policy (which restricts what resources a page can load), X-Content-Type-Options and Referrer-Policy harden your site against common attacks. A well-secured site is part of the trust baseline engines and users expect. On the indexing side, the X-Robots-Tag header lets you apply directives like noindex at the server level — crucially, this works for non-HTML resources like PDFs and images where you can't add a meta robots tag, giving you control the page markup can't. Together, good headers are a low-visibility, high-value configuration layer: they don't change what users see but meaningfully improve security posture and indexing control.

    How this check scores
    Pass: Reasonable security headers and robots controls in place.
    Warning: Some headers present, key ones (HSTS or CSP) missing.
    Fail: No meaningful security headers configured.

    FAQ

    HTTP security headers are directives a server includes in its responses to instruct the browser to behave more securely. Common ones include Strict-Transport-Security (HSTS), which forces browsers to use HTTPS and not fall back to insecure HTTP; Content-Security-Policy (CSP), which restricts what scripts and resources a page can load to mitigate cross-site scripting; X-Content-Type-Options, which stops browsers guessing content types; and Referrer-Policy, which controls referrer information. Together they harden your site against several classes of attack at the browser level, complementing HTTPS and clean code.

    Audit your page across all 9 checks in Infrastructure, Bots & DNS

    See which checks pass, warn or fail — in seconds.

    Run a free audit →
    ← Back to the full Infrastructure, Bots & DNS guide
    Free TrialContact