Security headers
dossier_headersFetch https:/// and return every response header, so you can review Strict-Transport-Security, Content-Security-Policy, X-Frame-Options, X-Content-Type-Options, Referrer-Policy and Permissions-Policy. Returns the final URL after redirects and the headers as served. One GET, 5 s timeout. For the redirect hops themselves use dossier_redirects. Returns JSON with a status field: {status:"ok", data, fetchedAt} on success, {status:"not_applicable", reason} when the thing is genuinely absent, {status:"timeout", ms}, or {status:"error", message} when it could not be determined. Treat not_applicable as a finding and error as unknown.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| domain | Yes | Public domain name, e.g. example.com. IP addresses, ports, paths and protocol prefixes are rejected. |