HTTP Headers Checker
This free HTTP headers checker requests a URL and lists every response header the server sends: status, content type, caching, compression, cookies and the security headers. Each security header (HSTS, Content-Security-Policy, X-Content-Type-Options, X-Frame-Options, Referrer-Policy, Permissions-Policy) is graded pass, needs work or missing, with the line to add. It suits developers and site owners.

HTTP Headers Checker
Technical SEO
About this tool
Response headers are the part of a web page nobody sees and everybody depends on. They tell browsers whether to cache the page, whether it may be framed by another site, which scripts may run, whether cookies are safe from scripts, and whether to insist on HTTPS. Missing security headers are the most common finding in any website security review, and most take one line of server configuration to fix.
The checker requests the URL from our server, follows up to three redirects, and prints the headers of the final response exactly as received, in a copyable box. It then grades the ones that matter: Strict-Transport-Security, Content-Security-Policy, X-Content-Type-Options, X-Frame-Options (or a frame-ancestors directive), Referrer-Policy, Permissions-Policy, cookie flags (Secure, HttpOnly, SameSite), Cache-Control, Content-Encoding and the version strings leaked by Server and X-Powered-By.
Headers can differ by path, by device and by whether a CDN serves the page, so check the pages that matter rather than only the homepage. A Content-Security-Policy is graded present or absent, not for strength, because a safe policy depends on the scripts your site really uses. Headers set by JavaScript or inside the HTML (meta http-equiv) are not response headers and do not appear here.
Frequently asked questions
Which security headers should every website send?
At minimum: Strict-Transport-Security on HTTPS sites, X-Content-Type-Options: nosniff, a framing rule (X-Frame-Options: SAMEORIGIN or Content-Security-Policy with frame-ancestors), and Referrer-Policy: strict-origin-when-cross-origin. A Content-Security-Policy and a Permissions-Policy are the next step. All of them are single lines in Nginx, Apache or your CDN settings.
What does HSTS do and is it safe to enable?
Strict-Transport-Security tells browsers to use HTTPS for your domain for the stated time, even when a link says http. It stops downgrade attacks and saves a redirect. Enable it only when every page and subdomain works over HTTPS, start with a short max-age such as 300, then raise it to 31536000 (a year) once you are sure.
Do security headers affect SEO?
Not directly: Google does not rank sites by headers. They matter for trust and safety, and HSTS can save one redirect. Caching and compression headers do affect speed, which is a ranking factor, so Cache-Control on static files and gzip or Brotli compression are worth fixing first.
Why does the checker show different headers from my browser?
Servers and CDNs vary headers by request: a logged-in session, a mobile user agent, a cached copy at the CDN edge or a different region can all change them. Our request comes from a server with a desktop browser user agent and no cookies, so compare it with a private browsing window.
Should I hide the Server and X-Powered-By headers?
Hide the version numbers at least. Announcing "Apache/2.4.29" or "PHP/7.4" tells attackers exactly which known vulnerabilities to try. The server name alone is harmless. In Nginx use server_tokens off; in Apache ServerTokens Prod; in PHP expose_php = Off removes X-Powered-By.
