HTTP header checker

See the raw response headers of a URL, and of every redirect on the way to it: status, Location, Server, caching, security and robots headers, with a quick audit of the ones that matter.

Headers worth checking

For redirects and SEO

  • Location: where a 3xx sends the client.
  • X-Robots-Tag: noindex or nofollow for non-HTML files such as PDFs; overrides nothing in the HTML but applies alongside it.
  • Link: <…>; rel="canonical": a canonical declared in HTTP, useful for PDFs.
  • Cache-Control on a 301: a long max-age makes the redirect stick in browsers.
  • Vary: if it includes User-Agent or Cookie, different visitors may get different redirects.

For security

  • Strict-Transport-Security: enforces HTTPS on return visits.
  • Content-Security-Policy, X-Content-Type-Options: nosniff, Referrer-Policy, Permissions-Policy.
  • Server and X-Powered-By: often reveal software versions; many teams trim them.

Headers are shown exactly as the server sent them to our checker, which requests with no cookies. Switch the user agent to see bot- or mobile-specific responses.

Questions

How do I check the HTTP headers of a website?

Enter the URL above and press Get headers. Every response in the redirect chain is listed with its full header set, and the final response gets a short audit of security and indexing headers. In a browser you can also open DevTools → Network and click the request.

Why do I see different headers in my browser?

Your browser sends cookies, may hit a cached copy or a different CDN edge, and may be served different content by user agent. Our requests are cookie-free first visits.

Can I see request headers too?

We send a standard GET with a User-Agent (selectable), Accept, Accept-Encoding and Accept-Language, and no cookies. Only response headers are shown because those are what the server controls.