📋

HTTP Headers Checker

An HTTP headers checker fetches a URL and shows the response headers the server sent back. Paste an address, press Check Headers, and you get the status code, the number of headers and a security score: github.com comes back 200 with 17 headers and 86%, while example.com comes back 200 with 9 headers and 0%.

Embed this tool on your website

× px

                        

💡 Integration Tip

Copy the embed code and paste it into your website HTML. The responsive version adapts to all screen sizes automatically.

1 rating
✓

Popular Tools

No more tools to show
Explore All Tools

Seeing a 301 or 302 with a Location header? Trace the whole redirect chain to see every hop down to the final page.

About HTTP Headers Checker

Type a page address into the box — the field adds https:// for you if you leave the scheme off — and press Enter or Check Headers. Eight chips underneath (google.com, github.com, cloudflare.com, amazon.com, facebook.com, twitter.com, netflix.com and apple.com) run the check straight away if you just want a reference point. The request is made by this site's server, not by your browser, so what comes back is what a plain client sees: no cookies of yours, no extensions, no signed-in session.

Three cards summarise the answer: HTTP Status, coloured green for 2xx, amber for 3xx and red otherwise; Headers Count; and Security Score. That score is simply how many of seven headers are present, as a percentage: Strict-Transport-Security, Content-Security-Policy, X-Content-Type-Options, X-Frame-Options, X-XSS-Protection, Referrer-Policy and Permissions-Policy. github.com scores 86% because six of the seven are there and Permissions-Policy is not.

The Security Headers Audit lists all seven with a tick or a cross, showing the header's value when it is present and a one-line description of what it does when it is not. Below that, Response Headers prints every field the server returned; the Filter headers box narrows the list by name or value as you type, and Copy puts the whole set on the clipboard. Recent keeps the last ten addresses you checked in your own browser storage, and Clear empties it.

Limits: it checks one public URL at a time, and private or reserved addresses are refused outright with "Private/reserved IP addresses are not allowed", so a router or a machine on your LAN cannot be probed from here. Only those seven headers are scored — a site can be perfectly well configured and still read 0%, as example.com does. There is no redirect-chain view, no bulk list and no scheduling, and the history never leaves your browser.

Use Cases

A developer rolling out a Content-Security-Policy: run the check before and after the deploy and watch content-security-policy move from a red cross to a tick in the Security Headers Audit.
A security reviewer sweeping a list of domains before a formal audit: the single Security Score number sorts the obviously unconfigured sites from the ones worth reading header by header.
An SEO verifying a migration: the HTTP Status card shows whether the address really answers 200 or is quietly redirecting, which a browser hides once it has followed the hop.
A support engineer confirming that a CDN sits in front of a site: example.com's response carries server: cloudflare along with cf-cache-status and cf-ray, all visible in the Response Headers list.
A student learning how the web works: pressing the github.com chip returns 17 real headers, which is a better introduction to caching, content type and security policy than any diagram.

How to use

1

Type the page address into the box — the scheme is optional, example.com becomes https://example.com — or click one of the eight site chips.

2

Press Enter or Check Headers and wait for the three cards: HTTP Status, Headers Count and Security Score.

3

Read the Security Headers Audit: a tick shows the header's value, a cross shows what the missing header would have done.

4

Scan the Response Headers list, narrowing it with the Filter headers box if the response is long.

5

Press Copy to take the whole header set as text; Recent keeps your last ten addresses, and Clear empties that list.

Pro Tips

  • You can leave the scheme off: type example.com and the field rewrites it to https://example.com before sending the request.
  • The eight site chips fire the check on click, so they are the fastest way to get a reference response to compare your own site against.
  • A high score is not a full audit: it counts seven header names and nothing about their values, so a Content-Security-Policy of unsafe-inline still scores as present.
  • Servers speaking HTTP/2 send field names in lower case, so the list shows strict-transport-security rather than Strict-Transport-Security — the audit matches case-insensitively, so the tick still appears.
  • Recent holds the last ten addresses in your own browser storage rather than on the server; Clear wipes it, and a private window starts empty.

Troubleshooting

Problem:

The check answers "Private/reserved IP addresses are not allowed".

Solution:

That is deliberate. The request is made from this site's server, so allowing private addresses would let the page probe internal networks on someone's behalf. Anything on 127.x, 10.x, 172.16-31.x or 192.168.x is refused. To read the headers of a device on your own LAN, use your browser's DevTools Network tab instead.

Problem:

The check answers "Connection failed: Could not resolve host".

Solution:

The hostname did not resolve: check the spelling, and check that you typed a domain rather than a search phrase. If the domain is new, DNS may not have propagated yet. The same message appears for a domain that has expired or has no A record.

Problem:

The Security Score reads 0% but the site clearly works.

Solution:

The score only counts seven header names, so a site that sets none of them scores zero however well it is run — example.com returns 200 with 9 headers and scores 0%. Read the Security Headers Audit for what is actually missing rather than treating the percentage as a verdict.

Problem:

The headers here do not match what Chrome DevTools shows me.

Solution:

Two different requests. This page asks from a clean server-side client with no cookies, no extensions and a different user agent, while DevTools shows your own session. A response that varies by Accept-Language, Accept-Encoding or a signed-in cookie will legitimately differ; check the vary header in the list.

Problem:

The Response Headers list goes empty while I type in the filter.

Solution:

Filter headers matches your text against both the field name and its value, in lower case, and hides everything else. A term such as "security" leaves only the policy headers, and a typo leaves nothing. Clear the box to bring the full list back.

Frequently Asked Questions

They are the name-and-value lines a server sends alongside a page, describing the response rather than being part of it: content-type says what the body is, cache-control says how long it may be reused, server names the software. This tool shows exactly those lines — 17 of them for github.com, 9 for example.com.

Paste the address into the box and press Check Headers, or press Enter. The page requests the URL from this site's server and prints the status code, the header count, a security score and the full list of response headers. No installation, no extension and no account is involved.

Use curl -I https://example.com for headers only, or curl -sD - -o /dev/null https://example.com to print the headers while discarding the body. Add -L to follow redirects and see the headers of every hop. This page does the same job when a terminal is not to hand, and formats the result.

Open DevTools with F12, go to the Network tab, reload the page, click the top request and read the Response Headers panel. That shows the headers as your own browser received them, cookies and extensions included; this tool asks from a clean server-side client instead, which is why the two lists can differ.

The seven this page audits: Strict-Transport-Security forces HTTPS, Content-Security-Policy restricts what may load, X-Content-Type-Options stops MIME sniffing, X-Frame-Options blocks framing, X-XSS-Protection is a legacy filter, Referrer-Policy controls what is sent in the Referer field, and Permissions-Policy limits browser features such as camera access.

Run the check and read the Security Headers Audit: each of the seven gets a tick with its actual value or a cross with a one-line explanation of what it would do. The Security Score above is the same thing as a percentage — six out of seven present gives 86%, as github.com does.

Because the body of a response says nothing about itself. Headers tell the browser what the content is, whether it may be cached, whether it must be fetched over HTTPS next time, which origins may run scripts on the page and whether the response may be shown inside a frame. Remove them and the browser has to guess.

As a field name, a colon and a value, one per line. Field names are case-insensitive, which is why a server speaking HTTP/2 sends them lower-cased: github.com returns strict-transport-security, not Strict-Transport-Security. Values can be long and comma-separated, as with a vary list or a Content-Security-Policy.

They are metadata, and part of every response, so nothing here reveals anything a visitor could not already see. What they can leak is infrastructure detail: example.com's answer carries server: cloudflare, cf-cache-status and cf-ray, which names the CDN in front of it. Trimming a Server header to hide a version is common practice.

There is no fixed number. Standard field names are registered centrally rather than frozen into the specification, and any server may add its own, which is why cf-ray and cf-cache-status show up on a Cloudflare response. What matters in practice is how many a given site returns: 17 for github.com and 9 for example.com in this tool.

FreeWebTools AI
Powered by free AI models · Full chat →