📋 HTTP Headers Checker

Inspect the real HTTP response headers sent by any URL, with key security headers highlighted.

Input

Results

Highlighted Headers

HeaderValue

All Response Headers

HeaderValue

How It Works

This fetches the URL from our edge function and returns the actual response headers received. Some headers — like Content-Security-Policy, Strict-Transport-Security, and X-Content-Type-Options — are highlighted because they directly affect a site's security posture. Note that intermediary proxies, CDNs, or the fetching environment itself can sometimes normalize or strip certain headers, so this may not always be byte-identical to what a browser sees directly.

Examples & Common Use Cases

  • Strict-Transport-Security tells browsers to always use HTTPS for this domain.
  • Content-Security-Policy restricts what resources a page is allowed to load.
  • Cache-Control and Content-Type are useful for debugging caching and content-rendering issues.