HTTP Header Inspector
Enter a URL to inspect its HTTP response headers and security header configuration.
Response
Security Headers
All Response Headers
About HTTP Header Inspection
This tool fetches the HTTP response headers from any public URL through our server-side API. It highlights important security headers and flags missing ones.
- Strict-Transport-Security: Enforces HTTPS connections
- Content-Security-Policy: Controls allowed content sources
- X-Content-Type-Options: Prevents MIME-type sniffing
- X-Frame-Options: Prevents clickjacking
- Referrer-Policy: Controls referrer information
- Permissions-Policy: Controls browser features
Response headers are where a surprising amount of behaviour is decided, and most of it is invisible until something breaks. Caching, security policy, compression and redirects all live here, and a header that is missing is as significant as one that is wrong. The security headers in particular fail silently: nothing warns you that a policy was never sent, the protection simply is not there.
Related tools
Something wrong out at the edge?
A lookup answering from the wrong record, a certificate that expires on a Sunday, a header that gives away more than it should. We look after servers, DNS and the delivery layer, and we set them up so the next surprise is caught before your users find it.
Ask about your infrastructure