Authorized Public Snapshot

Check security headers on a website you control

Start a free, one-time check of a website you control. You will need an account and access to its DNS settings to verify ownership before a check can run. The snapshot covers selected security headers, HTTPS redirects and TLS behaviour. See the fictional example below for how to explain a result to a client.

Enter a hostname only. This step validates the format locally and does not contact it.

You will be asked to create an account before adding and verifying this hostname. No check runs until you authorize it.

Example: documenting a security header fix

Fictional example for illustration. These values are not a live scan or a customer report.

Client and scope
Example Studio · example.com · authorization recorded for this hostname.
Before the fix
14 Sep 2026, 09:00 UTC: the HTTPS response did not include X-Content-Type-Options.
Remediation and owner
The hosting engineer added X-Content-Type-Options: nosniff to the response configuration.
Same check, after the fix
14 Sep 2026, 09:15 UTC: the response included X-Content-Type-Options: nosniff.
Evidence to retain
The hostname, rule, timestamps and before-and-after header observations, alongside the configuration change record.
Client-ready conclusion
The expected header was observed on the retest. This example does not assess other headers, subdomains, application vulnerabilities or overall website security.

How it works

  1. 1. Add the host. Create an account or open Properties and add the hostname.
  2. 2. Confirm authority. Publish the requested DNS TXT record so RemedyProof can verify control.
  3. 3. Run the free snapshot. The authorized, one-time read-only snapshot records bounded observations.

The snapshot covers HSTS, CSP framing or X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, and relevant cookie attributes alongside the HTTPS and TLS checks.

What the result means

The selected checks are part of a broader, bounded observation: a point-in-time result is not a security certification, compliance assessment, or penetration test. Results are retained for seven days, and the free snapshot does not start recurring monitoring.