All tools
Tool

HTTP Header Checker

Inspect HTTP response headers for any URL.

What Are HTTP Headers?

HTTP headers are key-value pairs sent between client and server with every request and response. They carry metadata about content type, caching policies, security settings, and encoding.

Important Security Headers

Strict-Transport-SecurityForces HTTPS connections.
X-Frame-OptionsPrevents clickjacking.
Content-Security-PolicyControls resource loading to reduce XSS risk.
X-Content-Type-OptionsPrevents MIME sniffing attacks.

Common Use Cases

  • Security auditing — check for missing security headers like HSTS, CSP, and X-Frame-Options that leave a site exposed to common attacks.
  • Debugging caching issues — inspect Cache-Control and ETag headers to understand why content isn't updating as expected.
  • Verifying server configuration — confirm which web server or technology stack a site is running based on returned headers.
  • CDN/proxy verification — check headers like CF-Ray or X-Served-By to confirm traffic is passing through a CDN as expected.

Example

A response missing Strict-Transport-Security and X-Content-Type-Options headers indicates the site is vulnerable to protocol downgrade and MIME-sniffing attacks — both fixable with a few server config lines.

Frequently Asked Questions

What are the most important security headers?

Strict-Transport-Security (HSTS), Content-Security-Policy (CSP), X-Frame-Options, and X-Content-Type-Options are widely considered baseline security headers.

Why don't I see a Server header?

Many servers are configured to hide or obscure this header intentionally, as a minor security-through-obscurity measure.

What does Cache-Control tell me?

It defines how long browsers and proxies should cache a response, which directly affects how quickly your users see updated content.

Can headers reveal my tech stack?

Yes — headers like X-Powered-By or Server often reveal the underlying framework or server software, which is why many production sites strip them.