Skip to content
ScriptGarden

HTTP Header Checker

Enter a web address to see the headers its server sends back, with advice on security, caching, compression and cookies.

Checked from our serverTopic: Technical SEO and Core Web VitalsFreeNo sign-upUpdated

What are HTTP response headers?

HTTP response headers are lines of information a web server sends along with every page, covering caching, compression, security rules and more. Checking them shows whether a site is protected against common attacks and set up to load quickly.

How it works

  1. 1

    Enter the address to check.

  2. 2

    Read the checklist for security, speed and information leaks.

  3. 3

    Open the full header list for the exact values.

  4. 4

    Ask your host or developer to change what is flagged.

Frequently asked questions

Which security headers matter most?

Strict-Transport-Security (always use HTTPS), X-Content-Type-Options (no file-type guessing), a framing rule (X-Frame-Options or CSP frame-ancestors), Referrer-Policy and a Content-Security-Policy.

Is a missing header a vulnerability?

Not by itself. These headers add layers of protection. Content-Security-Policy in particular needs care to set up, because a strict policy can break a site that was not prepared for it, so test before enforcing.

Why is showing the server version a problem?

Version numbers tell attackers which known flaws might apply. Most servers can be set to hide them.

Why can the result differ from my browser's?

A CDN or firewall may answer differently for different visitors, locations or logged-in users. This tool makes one anonymous request from our server.

Do you store the results?

No. The request is made, the headers are shown, and nothing is saved.

Related guides

Sources and further reading

More free tools