📋 HTTP Headers Checker
Inspect the real HTTP response headers sent by any URL, with key security headers highlighted.
Input
Results
Highlighted Headers
| Header | Value |
|---|
All Response Headers
| Header | Value |
|---|
How It Works
This fetches the URL from our edge function and returns the actual response headers received. Some headers — like Content-Security-Policy, Strict-Transport-Security, and X-Content-Type-Options — are highlighted because they directly affect a site's security posture. Note that intermediary proxies, CDNs, or the fetching environment itself can sometimes normalize or strip certain headers, so this may not always be byte-identical to what a browser sees directly.
Examples & Common Use Cases
- Strict-Transport-Security tells browsers to always use HTTPS for this domain.
- Content-Security-Policy restricts what resources a page is allowed to load.
- Cache-Control and Content-Type are useful for debugging caching and content-rendering issues.