See all HTTP headers your browser sends with every request — and check response headers from any website.
These 15 headers are sent with every page you visit
When a browser requests a web page, the server sends back HTTP headers alongside the actual page content — metadata describing things like the content type, caching rules, server software, and security policies that govern how the browser should handle the response.
Headers like Strict-Transport-Security force browsers to always use HTTPS for a domain, Content-Security-Policy restricts which scripts and resources a page can load to prevent injection attacks, and X-Frame-Options prevents a page from being embedded in a hidden iframe on another site. Their presence, or absence, is a quick signal of a site’s security posture.
Enter any URL and this tool fetches the raw response headers directly from the server, letting you inspect security configuration, caching behavior, or server software without needing browser developer tools or a command-line request.
Every response from a web server begins with headers: short name and value lines that tell the browser how to handle what follows. Visitors never see them, but they control caching, redirects, compression, cookies and security rules. When a page behaves oddly, such as an old version that keeps showing, a redirect that loops, or a file that opens instead of downloading, the headers usually explain why.
Strict-Transport-Security, Content-Security-Policy, X-Content-Type-Options, X-Frame-Options and Referrer-Policy protect visitors from HTTPS downgrades, injected scripts, content-type tricks, clickjacking and leaked referrer URLs. The security headers checker grades these for you.
What your server sends is not always what arrives. CDNs, caching plugins and firewalls can add, strip or rewrite headers on the way out. If a header you configured does not appear here, something between your server and the internet is removing or replacing it, and that layer is where to fix it.