Try:
Enter a URL and press Check
Enter a URL and press Check to list the response headers

How to use the HTTP Header Checker

  1. Enter a URL and press "Check".
  2. The top shows the status code, security header score, response time and server software.
  3. Yellow items under "Security headers" are recommended additions.
  4. Press "Copy" for a plain-text header list.

Examples

Recommended security headers (Nginx)

Input
Missing HSTS, X-Content-Type-Options, Referrer-Policy
Output
add_header Strict-Transport-Security "max-age=31536000; includeSubDomains" always;
add_header X-Content-Type-Options "nosniff" always;
add_header Referrer-Policy "strict-origin-when-cross-origin" always;

What the six security headers do

Strict-Transport-SecurityTells browsers to always use HTTPS, preventing downgrade attacks.
Content-Security-PolicyRestricts where scripts and resources may load from — the strongest defense against XSS.
X-Content-Type-Optionsnosniff stops browsers from guessing file types.
X-Frame-OptionsPrevents the page being framed by other sites (clickjacking); CSP frame-ancestors also works.
Referrer-PolicyControls how much of the URL is sent when users follow links to other sites.
Permissions-PolicyLimits access to camera, microphone, geolocation and other browser features.

Specs & key facts

ShowsStatus code, response time, all response headers
Security checksHSTS, CSP, X-Content-Type-Options, X-Frame-Options, Referrer-Policy, Permissions-Policy
Caching checksCache-Control, Expires, ETag, Last-Modified, Age, Vary, Content-Encoding
RedirectsFollowed (up to 10); headers of the final URL are shown
LimitsPublic URLs only, 20 checks per minute
PriceFree, no sign-up

FAQ

Does a low security header score hurt SEO?

Security headers are not a direct ranking factor, but HTTPS with HSTS keeps users and crawlers on secure connections, and headers like CSP reduce the risk of a compromise that gets your site flagged.

Why are the results different from my browser's developer tools?

Servers may vary headers by User-Agent, cookies or region, and CDNs have different edges. This tool makes a logged-out request from our server.

How should Cache-Control be set?

Versioned static files (CSS, JS, images) can use public, max-age=31536000, immutable; HTML pages usually use a short max-age or no-cache so updates appear promptly.