The Observatory moved to MDN and grades your HTTP security headers — and it's great at that. MySSL grades the same headers, then adds your SSL/TLS grade, email auth and CT, and keeps monitoring them with alerts. All free.
No card. Header checks need no signup; an account adds re-scans and grade-drop alerts.
Mozilla's Observatory was relaunched on MDN as the HTTP Observatory (announced July 2024) at developer.mozilla.org/en-US/observatory; the old observatory.mozilla.org is deprecated. It grades your HTTP security headers with a score and letter grade, and its MDN documentation on fixing each finding is the best around — genuinely a great place to learn.
Its scope is HTTP headers. It doesn't grade your full SSL/TLS configuration or your email authentication, and it's an on-demand scan rather than something that watches your site. MySSL grades the same headers and covers the rest, with monitoring and alerts on top.
| Capability | MySSL.info | MDN HTTP Observatory |
|---|---|---|
| Price | Free | Free |
| HTTP security headers grade | Yes | Yes |
| Educational docs for fixing headers | Guides in /learn | Best-in-class (MDN) |
| Full SSL/TLS certificate grade | Yes | No — headers only |
| Email auth (SPF / DKIM / DMARC) | Yes | No |
| Certificate Transparency log search | Yes | No |
| Continuous monitoring + grade-drop alerts | Yes | No — one-off scan |
| Free JSON API | Yes (anon + free key) | Yes (v2 API) |
If your goal is to learn exactly why each header matters and how to configure it, the MDN HTTP Observatory — backed by MDN Web Docs — is the best teaching resource on security headers, and its updated scoring is a solid reference. Use it to understand the fixes; use MySSL to keep the headers (and your SSL, email and CT) graded and monitored over time.
It was relaunched and moved to MDN as the HTTP Observatory, at developer.mozilla.org/en-US/observatory (announced in July 2024). The original observatory.mozilla.org code is deprecated; a rewritten backend now powers the version on MDN with updated scoring.
It assesses your HTTP security headers — Content-Security-Policy, Strict-Transport-Security, X-Frame-Options, cookies and more — and returns a score and a letter grade, backed by excellent MDN documentation on how to fix each finding. It does not grade your full SSL/TLS certificate configuration or your email authentication.
Both are free. MySSL's security-headers checker grades the same core headers on an A+ to F scale, and additionally gives you an SSL/TLS grade, email authentication checks (SPF, DKIM, DMARC) and Certificate Transparency search — one report instead of several tools.
No — it's an on-demand scan. MySSL can re-scan on a schedule, keep history, and alert you when a header grade drops, via email, Slack, Discord, Telegram or webhook.
Yes — the MDN HTTP Observatory has a v2 API. MySSL also offers a free JSON headers API (GET /headers/check?q=domain, returning the grade on the X-Grade header), plus SSL and email endpoints, with an anonymous tier and a free key for higher limits.
Use the MDN HTTP Observatory for its outstanding educational docs when you're learning to fix headers; it's the best teaching resource for that. Use MySSL when you want one grade across SSL, headers, email and Certificate Transparency, plus continuous monitoring and alerts. They pair well.
We're new and growing — your feedback helps us improve.