---
title: "Bulk Security Header Checker — free tool"
description: "Free bulk security header scanner. Check HSTS, CSP, X-Frame-Options across 25 URLs at once. Per-URL grade A+ to F. CSV export."
canonical: "https://lemwatch.com/tools/bulk-security-headers"
source: "https://lemwatch.com"
---

# Bulk Security Header Checker

> Scan HTTP security headers across up to 25 URLs in one batch. HSTS, CSP, X-Frame-Options, Permissions-Policy — graded A+ to F.

Security headers are easy to misconfigure across a portfolio. One tenant ships without HSTS, one storefront strips CSP from a CDN rule, one staging site got promoted to prod with default headers. Bulk header checks catch all of that in one paste.

 ## What this tool does

 Paste up to 25 URLs. We fetch each one, read the HTTP response headers (without rendering the page), and compute a per-URL grade based on the same checklist as the single-URL Security Header Checker. The result is a table of grades you can sort and export.

 ## What we look for

 Strict-Transport-Security (HSTS) — forces HTTPS. Content-Security-Policy (CSP) — the biggest single defence against XSS. X-Frame-Options / frame-ancestors — prevents clickjacking. X-Content-Type-Options: nosniff — kills MIME confusion attacks. Referrer-Policy — limits data leakage in the Referer header. Permissions-Policy — locks down browser APIs the site does not need. Each missing or weak header costs points; the grade comes out the other side.

 ## Why this matters at scale

 Single-URL header checks are great for one site. Multi-tenant SaaS, agency portfolios, and ecommerce platforms with multiple storefronts need fleet-wide visibility — and that visibility cannot be 'log into each site individually'. Bulk header checks turn the audit into one paste.

## What this tool checks

- Strict-Transport-Security (HSTS) presence and max-age
- Content-Security-Policy presence and major directives
- X-Frame-Options / frame-ancestors
- X-Content-Type-Options
- Referrer-Policy and Permissions-Policy
- Per-URL composite grade

## Why it matters

 Security headers are quiet but critical — missing ones leave sites open to clickjacking, XSS injection, and downgrade attacks. Across a multi-site portfolio, headers drift silently as new pages and tenants ship.

## How to fix what it finds

- Group the CSV by missing header and ship one platform-level fix (HSTS at the edge, CSP at the CDN)
- Start with HSTS — it is one line and prevents 90% of downgrade attacks
- Add CSP in report-only mode first; review violations for 2 weeks before enforcing
- Use the single-URL Security Header Checker on the lowest-graded row to get example header values

## Methodology

 We send a single GET request to each URL with a normal browser User-Agent and follow up to 5 redirects. We read the final response headers and run them through the same scoring matrix as the single-URL tool: HSTS presence + max-age + includeSubDomains + preload, CSP presence + key directive coverage, X-Frame-Options or frame-ancestors, X-Content-Type-Options, Referrer-Policy strictness, and Permissions-Policy. We do not parse or execute the HTML — headers only. The grade is computed deterministically: each header carries a weight, and the composite weighted score maps to A+/A/B/C/D/F bands. Rows are returned in the order you submitted them so you can match against your source list.

## Frequently asked questions

### Why does the grade differ from another scanner?

 Different scanners weight headers differently. We follow the same rubric as the single-URL Security Header Checker on this site for consistency.

### Does this check the body of the page?

 No. We only read HTTP response headers. CSP nonces, inline-script policies, and other body-level concerns need the single-URL deep dive.

### How many redirects will it follow?

 Up to 5. URLs with redirect loops will fail with a redirect-loop error.

### Will this trigger rate limits on my sites?

 Unlikely — we issue one GET per URL with a 1-second delay between batch starts. If your WAF blocks unknown user-agents, allowlist requests from LemWatch.

### Can I check internal/staging URLs?

 Only if they are reachable from the public internet. URLs behind a VPN or auth wall will return errors.

### What does the CSV include?

 URL, status, grade summary, and any error message. Click into the row to see all individual header values in the single-URL tool.


## Related

- [All free tools](https://lemwatch.com/tools)
- [Security Headers](https://lemwatch.com/tools/security-header-checker)
- [Bulk SSL Certificate Checker](https://lemwatch.com/tools/bulk-ssl-checker)
- [SSL Checker](https://lemwatch.com/tools/ssl-checker)
- [Bulk DNS Lookup Tool](https://lemwatch.com/tools/bulk-dns-lookup)
- [Bulk Meta Tag Checker](https://lemwatch.com/tools/bulk-meta-tags)
- [Lemwatch pricing](https://lemwatch.com/pricing)
- [All monitoring checks](https://lemwatch.com/features)
