HTTP Headers Checker
See the HTTP response headers a website sends — for every redirect hop — and get a security grade with clear fixes for missing headers.
We only request the URL you enter. Nothing is stored.
How to use the HTTP Headers Checker
Enter a URL
Any page, image or API endpoint.
See every header
Status, caching, compression and server headers for each hop.
Get a grade
Security headers graded A+ to F with example values.
Why use our HTTP Headers Checker?
Security grade
HSTS, CSP, X-Frame-Options, nosniff, Referrer and Permissions policies.
Every hop
Headers of each redirect in the chain.
Info leaks
Flags headers that reveal server software versions.
Cache & compression
Cache-Control, ETag, gzip/Brotli at a glance.
User agents
Check as Chrome, iPhone or Googlebot.
Copy all
Copy raw headers with one click.
Frequently asked questions
Everything you need to know about the HTTP Headers Checker.
Back to the toolWhat are HTTP headers?
HTTP headers are extra information a server sends with every response — for example the content type, caching rules, cookies and security policies.
Why do security headers matter?
They tell browsers how to protect visitors — for example to always use HTTPS (HSTS) or to block clickjacking (X-Frame-Options). They are quick wins for website security.
How do I add security headers?
On Apache add them in .htaccess with “Header always set …”, on Nginx with “add_header …”, or in your framework (Laravel middleware, WordPress plugin).
Why hide the X-Powered-By header?
It reveals your server software and version, which helps attackers look for known vulnerabilities.
What does an A+ grade need?
HTTPS plus all six key security headers: HSTS, Content-Security-Policy, X-Frame-Options, X-Content-Type-Options, Referrer-Policy and Permissions-Policy.
You may also like
Have a project in mind? Let’s build it together.
Get a free consultation and a fixed-price quote within 24 hours.