HTTP Header Checker

Fetch any URL and read its response headers, with the security headers checked against what a well-configured site should be sending.

What response headers tell you

Headers carry the decisions a server has made that never appear in the page itself: how long a response may be cached, whether it was served from a CDN edge, which compression was applied, whether a redirect happened and whether it was permanent.

That makes them the first thing to check when behaviour does not match expectation. A page serving stale content, a redirect chain costing you three round trips, or a CDN miss on every request are all visible in the headers and invisible in the HTML.

The security headers worth having

Strict-Transport-Security tells browsers to use HTTPS for your domain for a stated period, closing the window where a first plain-HTTP request can be intercepted. Content-Security-Policy limits where scripts may load from and is the control that decides how damaging a cross-site scripting bug turns out to be.

X-Content-Type-Options with the value nosniff stops browsers second-guessing your declared content types. X-Frame-Options and the frame-ancestors CSP directive prevent your pages being embedded in someone else site, which is what clickjacking depends on. Referrer-Policy controls how much of your URL is leaked to third parties - which matters whenever a path contains a token or an identifier.

Permissions-Policy declares which browser features a page may use, so camera and microphone access cannot be requested by anything you did not intend to allow.

Checking headers you do not control

Running this against a vendor or a partner before integrating is a quick way to judge how seriously they take their own configuration. It is also the fastest way to see how a competitor CDN is set up, or to confirm that a third-party script host is not serving with a content type that will be sniffed.

Frequently asked questions

Which security headers should every site send?
Strict-Transport-Security, Content-Security-Policy, X-Content-Type-Options, a framing restriction via X-Frame-Options or frame-ancestors, and Referrer-Policy. Permissions-Policy is worth adding wherever device access is a concern.
What does nosniff actually do?
It stops browsers guessing a content type that differs from the one you declared. Without it, a file served with the wrong type can be interpreted as a script, which is a real attack path.
Is a missing Content-Security-Policy serious?
It means any cross-site scripting bug you have is maximally damaging. CSP does not prevent XSS; it limits what an injected script can do and where it can send data.
Can I check headers for a site I do not own?
Yes. Response headers are public information returned to every visitor, so checking any URL is entirely ordinary.