# IndieHeaders > Check the security headers a public site sends: HSTS, CSP, framing, content type, referrer, and permissions, with the line to add for each gap. IndieHeaders is a free, one-input web utility for indie makers at indieheaders.com. It takes one url, for example https://example.com/, and answers in about ten seconds. Every answer names its source next to it. No account, no card, no premium plan, no upgrade nag, no hidden paywall. Private lookup activity is never published, and nothing on the page counts anyone. Every page is static HTML, and each link below is that page as Markdown or plain text. Made by turushan, https://twitter.com/turushan. ## Pages - [IndieHeaders](https://indieheaders.com/index.md): what the tool checks, what it takes, and what it promises - [More tools](https://indieheaders.com/tools.md): the other tools by turushan, one line each - [Notes](https://indieheaders.com/blog.md): the posts, newest first ## Notes - [Why IndieHeaders exists](https://indieheaders.com/blog/why-indieheaders-exists.md): See which security headers your site sends, and the exact line for each one missing. ## Policies - [security.txt](https://indieheaders.com/.well-known/security.txt): how to report a vulnerability, in the RFC 9116 shape