HTTP header checker
Every response header a URL sends, exactly as sent and explained — with a security-header grade, the cache policy in one sentence, and a cookie-flag audit.
What this measures
This checker requests a URL the way a browser does and lists every HTTP response header it sends back, exactly as sent, each with a plain-English explanation. It grades the six security headers browsers rely on, reads the caching policy in one sentence, audits cookie flags, and names the CDN in front — the response metadata that decides how secure, cacheable and fast a page is.
How to read your result
- Security checklist
- Strict-Transport-Security, Content-Security-Policy, X-Content-Type-Options, frame protection, Referrer-Policy and Permissions-Policy. Each costs nothing to send; together they block downgrade attacks, script injection, clickjacking and data leaks.
- Cache policy
- Cache-Control decides whether the browser and any CDN may reuse the response and for how long. no-store means every visit hits the server; a long max-age on HTML means updates take time to appear.
- Server & CDN
- Headers like server, via, cf-ray or x-served-by reveal the web server and the CDN in front. Host-specific cache headers often name the hosting provider outright.
- Cookies
- Each Set-Cookie is checked for Secure (HTTPS only), HttpOnly (hidden from scripts) and SameSite (cross-site sending rules).
Common causes & fixes
- Missing HSTS
- Add Strict-Transport-Security: max-age=31536000 once HTTPS works everywhere on the domain. Add includeSubDomains only when every subdomain is on HTTPS too.
- No compression
- If HTML arrives without a content-encoding of br or gzip, enable compression in the web server or CDN — it typically cuts HTML transfer size by well over half.
- Leaky version headers
- x-powered-by and detailed server versions help attackers match known vulnerabilities. Most stacks can drop them with one config line.
- Accidental noindex
- An x-robots-tag: noindex header keeps the URL out of Google even when the HTML looks fine — a common leftover from staging sites.
Frequently asked questions
How do I check a website's HTTP headers?
Enter the URL above. The checker sends a normal GET request, follows any redirects, and shows the final response's headers with an explanation for each.
Which security headers should every site have?
Strict-Transport-Security, Content-Security-Policy, X-Content-Type-Options: nosniff, X-Frame-Options (or CSP frame-ancestors), Referrer-Policy and Permissions-Policy.
Why don't I see the headers my browser shows?
Some headers vary by request — cookies, language, device or a CDN's location. This check is one request from a server, without cookies, so personalized headers can differ.
Can headers affect SEO?
Yes, a few directly: x-robots-tag can block indexing, Link can declare a canonical URL, and status codes plus caching and compression shape how fast pages load for visitors and crawlers.