This nginx config checker reviews a pasted server block or nginx.conf for the mistakes that most often break sites or weaken security. It runs entirely in your browser, so configuration details never leave your computer. Each finding shows the line number, what is wrong and a suggested replacement, and the result is a quick second opinion before you run nginx -t and reload.
Short answer: Paste the configuration and press Check. The checker flags missing semicolons and unbalanced braces, TLS 1.0 or 1.1 still enabled, HTTPS servers without HSTS, port 80 servers that do not redirect, the add_header inheritance trap, directory listing, PHP passed to FastCGI without try_files $uri =404, proxies that do not pass the Host header, and missing rules for hidden files such as .git and .env.
Table of Contents
The add_header trap
nginx inherits add_header directives from the server block only when a location block defines none of its own. Add a single Cache-Control header inside location / and every security header set at server level disappears for that location. The checker warns whenever both levels use add_header; fix it by repeating the headers in the location or putting them in an include file used in both places.
Checks it runs
- Syntax: lines without a closing semicolon or brace, and brace balance.
- TLS:
ssl_protocolscontaining SSLv3, TLSv1 or TLSv1.1; certificates that may lack the intermediate chain. - Headers: missing Strict-Transport-Security on HTTPS servers; server_tokens not disabled.
- Redirects: port 80 server blocks without a 301 to HTTPS.
- Pitfalls:
ifinside location, root inside location, autoindex on, fastcgi_pass without try_files, proxy_pass without Host header, no deny rule for dotfiles, default upload size.
Always confirm on the server
Static checks cannot see included files, variables or the modules compiled into your build. After fixing the findings, run nginx -t, then systemctl reload nginx, and check the live headers with the website status tool.
nginx -t
nginx -T | less # full merged configuration including includes
systemctl reload nginx
Nginx config checker at a glance


Official documentation: nginx documentation, RFC 8996: deprecating TLS 1.0 and 1.1.
Related tools: systemd unit generator · Website status and headers · SSL certificate checker.
Frequently asked questions
Is my configuration uploaded anywhere?
No. The checks run in JavaScript in your browser and nothing is sent to our server, so it is safe to paste configurations that contain internal hostnames or paths.
Does this replace nginx -t?
No. nginx -t parses the real configuration with all includes and modules. This checker catches common logic and security mistakes that nginx -t accepts as valid.
Why is TLSv1 flagged when some clients still need it?
TLS 1.0 and 1.1 are deprecated by RFC 8996 and disabled in current browsers. Keeping them enabled weakens the server for everyone to support clients that are almost gone.