How to use the HTTP Header Checker
- Enter a URL and press "Check".
- The top shows the status code, security header score, response time and server software.
- Yellow items under "Security headers" are recommended additions.
- Press "Copy" for a plain-text header list.
Examples
Recommended security headers (Nginx)
Missing HSTS, X-Content-Type-Options, Referrer-Policy
add_header Strict-Transport-Security "max-age=31536000; includeSubDomains" always;
add_header X-Content-Type-Options "nosniff" always;
add_header Referrer-Policy "strict-origin-when-cross-origin" always;
What the six security headers do
| Strict-Transport-Security | Tells browsers to always use HTTPS, preventing downgrade attacks. |
|---|---|
| Content-Security-Policy | Restricts where scripts and resources may load from — the strongest defense against XSS. |
| X-Content-Type-Options | nosniff stops browsers from guessing file types. |
| X-Frame-Options | Prevents the page being framed by other sites (clickjacking); CSP frame-ancestors also works. |
| Referrer-Policy | Controls how much of the URL is sent when users follow links to other sites. |
| Permissions-Policy | Limits access to camera, microphone, geolocation and other browser features. |
Specs & key facts
| Shows | Status code, response time, all response headers |
|---|---|
| Security checks | HSTS, CSP, X-Content-Type-Options, X-Frame-Options, Referrer-Policy, Permissions-Policy |
| Caching checks | Cache-Control, Expires, ETag, Last-Modified, Age, Vary, Content-Encoding |
| Redirects | Followed (up to 10); headers of the final URL are shown |
| Limits | Public URLs only, 20 checks per minute |
| Price | Free, no sign-up |
FAQ
Does a low security header score hurt SEO?
Security headers are not a direct ranking factor, but HTTPS with HSTS keeps users and crawlers on secure connections, and headers like CSP reduce the risk of a compromise that gets your site flagged.
Why are the results different from my browser's developer tools?
Servers may vary headers by User-Agent, cookies or region, and CDNs have different edges. This tool makes a logged-out request from our server.
How should Cache-Control be set?
Versioned static files (CSS, JS, images) can use public, max-age=31536000, immutable; HTML pages usually use a short max-age or no-cache so updates appear promptly.