Emergency server help: get in touch

nginx Config Checker: Find Security and Syntax Mistakes

Static review of an nginx configuration in your browser: syntax slips, old TLS protocols, missing HSTS and redirects, add_header inheritance, PHP-FPM and proxy pitfalls, with suggested fixes by line.

Status
Live
Last updated
October 3, 2026

This nginx config checker reviews a pasted server block or nginx.conf for the mistakes that most often break sites or weaken security. It runs entirely in your browser, so configuration details never leave your computer. Each finding shows the line number, what is wrong and a suggested replacement, and the result is a quick second opinion before you run nginx -t and reload.

Short answer: Paste the configuration and press Check. The checker flags missing semicolons and unbalanced braces, TLS 1.0 or 1.1 still enabled, HTTPS servers without HSTS, port 80 servers that do not redirect, the add_header inheritance trap, directory listing, PHP passed to FastCGI without try_files $uri =404, proxies that do not pass the Host header, and missing rules for hidden files such as .git and .env.

The add_header trap

nginx inherits add_header directives from the server block only when a location block defines none of its own. Add a single Cache-Control header inside location / and every security header set at server level disappears for that location. The checker warns whenever both levels use add_header; fix it by repeating the headers in the location or putting them in an include file used in both places.

Checks it runs

  • Syntax: lines without a closing semicolon or brace, and brace balance.
  • TLS: ssl_protocols containing SSLv3, TLSv1 or TLSv1.1; certificates that may lack the intermediate chain.
  • Headers: missing Strict-Transport-Security on HTTPS servers; server_tokens not disabled.
  • Redirects: port 80 server blocks without a 301 to HTTPS.
  • Pitfalls: if inside location, root inside location, autoindex on, fastcgi_pass without try_files, proxy_pass without Host header, no deny rule for dotfiles, default upload size.

Always confirm on the server

Static checks cannot see included files, variables or the modules compiled into your build. After fixing the findings, run nginx -t, then systemctl reload nginx, and check the live headers with the website status tool.

nginx -t
nginx -T | less        # full merged configuration including includes
systemctl reload nginx

Nginx config checker at a glance

nginx Config Checker summary card: Paste the configuration and press Check.
In short: Paste the configuration and press Check.
nginx Config Checker questions answered: Is my configuration uploaded anywhere? Does this replace nginx -t?
Answers: Is my configuration uploaded anywhere? Does this replace nginx -t?

Official documentation: nginx documentation, RFC 8996: deprecating TLS 1.0 and 1.1.

Related tools: systemd unit generator · Website status and headers · SSL certificate checker.

Frequently asked questions

Is my configuration uploaded anywhere?

No. The checks run in JavaScript in your browser and nothing is sent to our server, so it is safe to paste configurations that contain internal hostnames or paths.

Does this replace nginx -t?

No. nginx -t parses the real configuration with all includes and modules. This checker catches common logic and security mistakes that nginx -t accepts as valid.

Why is TLSv1 flagged when some clients still need it?

TLS 1.0 and 1.1 are deprecated by RFC 8996 and disabled in current browsers. Keeping them enabled weakens the server for everyone to support clients that are almost gone.

Free website test

Is your website set up right?

Check SSL, security headers, redirects, robots.txt, sitemap, llms.txt and security.txt in one test. It takes about 30 seconds.