HTTP Header Checker
Inspect HTTP response headers for any URL.
What Are HTTP Headers?
HTTP headers are key-value pairs sent between client and server with every request and response. They carry metadata about content type, caching policies, security settings, and encoding.
Important Security Headers
Common Use Cases
- Security auditing — check for missing security headers like HSTS, CSP, and X-Frame-Options that leave a site exposed to common attacks.
- Debugging caching issues — inspect Cache-Control and ETag headers to understand why content isn't updating as expected.
- Verifying server configuration — confirm which web server or technology stack a site is running based on returned headers.
- CDN/proxy verification — check headers like CF-Ray or X-Served-By to confirm traffic is passing through a CDN as expected.
Example
A response missing Strict-Transport-Security and X-Content-Type-Options headers indicates the site is vulnerable to protocol downgrade and MIME-sniffing attacks — both fixable with a few server config lines.
Frequently Asked Questions
What are the most important security headers?
Strict-Transport-Security (HSTS), Content-Security-Policy (CSP), X-Frame-Options, and X-Content-Type-Options are widely considered baseline security headers.
Why don't I see a Server header?
Many servers are configured to hide or obscure this header intentionally, as a minor security-through-obscurity measure.
What does Cache-Control tell me?
It defines how long browsers and proxies should cache a response, which directly affects how quickly your users see updated content.
Can headers reveal my tech stack?
Yes — headers like X-Powered-By or Server often reveal the underlying framework or server software, which is why many production sites strip them.