Autonomous Agentic AI Pipeline

Free browser tool / response headers

HTTP header checker

See what a server sends and what it means.

Enter a public https URL or paste a block of response headers. The checker lists the header lines it receives, groups them, and reads the security, caching, cookie and robots headers. Each finding links to MDN, an RFC or another primary source.

A finding is a prompt to look at a header. It is not a vulnerability scan, and it says nothing about rankings or indexing.

Check a URL

The URL goes to our fetch service. It makes one GET request and returns the response headers only, never the page body. Limits are https on port 443, 5 redirects, 8 seconds, 100 headers and 2,000 characters per value. Cookie values are masked.

Paste response headers

Pasted text stays in this browser. Use the output of curl -s -D - -o /dev/null https://your-site/ or copy the response headers from the Network panel of your browser. Up to 200,000 characters. Ctrl+Enter or Cmd+Enter runs the check.

Rules / every check has a source

What the checker looks at

The checker reads values, not only names. The table lists each check and the document it comes from. Where a header is present and no rule applies, the report shows it in the table without a finding.

HeaderWhat is checkedSource
strict-transport-securityPresent. max-age is a number, is not zero, and is at least 31536000 seconds (1 year). includeSubDomains. With preload, max-age must be at least 31536000 and includeSubDomains must be present.MDN, RFC 6797, hstspreload.org
content-security-policyAn enforced policy is present. A report-only policy alone is flagged, because it monitors violations without enforcing the policy. The directives are not graded.MDN, MDN, report-only
x-content-type-optionsThe value is nosniff, the only directive MDN lists.MDN
x-frame-options, frame-ancestorsX-Frame-Options is DENY or SAMEORIGIN. ALLOW-FROM is obsolete and modern browsers ignore the header when it is used. When an enforced policy has frame-ancestors, X-Frame-Options is ignored.MDN, CSP Level 3
referrer-policyThe value is a defined policy. unsafe-url and no-referrer-when-downgrade are called out. Without the header, browsers use strict-origin-when-cross-origin.MDN
permissions-policyPresent or not. The directives are not graded. MDN marks the header as experimental.MDN
cross-origin-opener-policy, cross-origin-embedder-policy, cross-origin-resource-policyThe value is one that MDN lists for the header.MDN, COOP, COEP, CORP
cache-controlno-store next to public, max-age, s-maxage or immutable. public next to private. max-age given twice with different values. immutable without max-age. Expires next to max-age. No Cache-Control at all, which allows heuristic freshness.RFC 9111, RFC 8246, MDN
set-cookieSecure, HttpOnly and SameSite on each cookie. SameSite=None without Secure. The __Host- and __Secure- name prefix rules. Cookie values are masked and never shown.MDN
x-robots-tagnoindex, nofollow and none are called out, and so is a rule addressed to one crawler. For the full rule list see the X-Robots-Tag reference.Google
content-typePresent. For text/html, whether a charset parameter is given.RFC 9110, HTML Standard
server, x-powered-byA version number in Server, in paste mode only. X-Powered-By present.RFC 9110, OWASP
x-xss-protectionAn enabled filter is noted. MDN recommends Content-Security-Policy instead.MDN

Get the headers yourself

  1. In a terminal, curl -s -D - -o /dev/null https://your-site/ prints the headers of a GET request. curl -sI sends a HEAD request instead, and some servers answer HEAD differently.

  2. In a browser, open the developer tools, select the Network panel, reload the page, select the document request and copy the response headers.

  3. Paste the block above. The first line with the status code is optional. Request lines from curl -v output are skipped.

Related tools on this site are the meta robots checker, the robots.txt checker and the canonical tag checker.

Data / 20 sites, one GET each, 10 October 2026

A 20 site header snapshot

On 10 October 2026 each of 20 hosts was fetched once with one HTTPS GET to its root URL. The table counts how many of the 20 responses carried each of eight security headers. The hosts were picked by hand as sites that developers use. They are documentation, language, runtime and framework sites, GitHub, Hacker News and Cloudflare, two test hosts (example.com and httpbin.org), plus www.google.com and en.wikipedia.org. This is not a random sample and it does not describe the web as a whole.

Security headerSites sending it, of 20Share of the 20
strict-transport-security1470%
x-content-type-options1050%
content-security-policy840%
x-frame-options840%
referrer-policy630%
cross-origin-opener-policy210%
cross-origin-resource-policy210%
permissions-policy15%

Source for every figure in this section is header-survey-2026-10-10.json, 20 hosts, one HTTPS GET each, captured 10 October 2026.

In this capture www.google.com sent no Strict-Transport-Security header. Of the 7 responses whose Server value was cloudflare, 5 carried Strict-Transport-Security and 2 did not (example.com and astro.build). 5 of the 20 responses carried none of the eight headers (example.com, httpbin.org, blog.rust-lang.org, astro.build and www.rust-lang.org). One GET per host is a single observation, so read each row as what that one response contained, not as a statement about the site.

The 20 hosts and what each response carried

HostOf the eightHeaders present
example.com0none
httpbin.org0none
developer.mozilla.org5strict-transport-security, x-content-type-options, content-security-policy, x-frame-options, referrer-policy
www.google.com1x-frame-options
en.wikipedia.org3strict-transport-security, x-content-type-options, content-security-policy
github.com5strict-transport-security, x-content-type-options, content-security-policy, x-frame-options, referrer-policy
news.ycombinator.com5strict-transport-security, x-content-type-options, content-security-policy, x-frame-options, referrer-policy
www.python.org2strict-transport-security, x-frame-options
nodejs.org2strict-transport-security, x-content-type-options
blog.rust-lang.org0none
web.dev3strict-transport-security, x-content-type-options, content-security-policy
developers.cloudflare.com3strict-transport-security, x-content-type-options, content-security-policy
www.cloudflare.com8strict-transport-security, x-content-type-options, content-security-policy, x-frame-options, referrer-policy, cross-origin-opener-policy, cross-origin-resource-policy, permissions-policy
tailwindcss.com1strict-transport-security
vitejs.dev1strict-transport-security
nextjs.org5strict-transport-security, x-content-type-options, content-security-policy, x-frame-options, referrer-policy
astro.build0none
www.rust-lang.org0none
deno.com6strict-transport-security, x-content-type-options, x-frame-options, referrer-policy, cross-origin-opener-policy, cross-origin-resource-policy
bun.sh1strict-transport-security

Method. One HTTPS GET per host on 10 October 2026, recorded as the host, the final status, the list of the eight headers present, the Server value and whether Set-Cookie was sent. The data file was saved at 05:24 UTC. It does not record the request times or the User-Agent string. vitejs.dev redirects to vite.dev and is recorded with status 200, so redirects were followed. As a check, 12 of the 20 hosts were fetched again with curl (GET) at 07:43 UTC the same day, and all 12 returned the same set of the eight headers.

Limits

  • URL mode shows what the server sent to our fetch service. The request comes from a Cloudflare data centre with the User-Agent AIWebsitePipeline-HeaderChecker/1.0. A server can send different headers to your browser. In a test on 10 October 2026 with 6 large sites, 2 answered the fetch service with an error status (HTTP 429 and HTTP 419) while a direct curl request received HTTP 200.

  • Cloudflare carries the request and changes part of the answer. The Server value is replaced, cf-ray and cf-cache-status are added, content-encoding, content-length, accept-ranges and alt-svc can be missing, and a strong ETag can arrive as a weak one (W/ prefix). The report marks these rows as "fetch service". Paste mode has no such changes.

  • In URL mode each Set-Cookie line is kept as its own row. Other repeated header lines arrive joined into one value with commas, which HTTP allows. RFC 9110, section 5.3. Paste mode keeps every line you paste.

  • The fetch service returns at most 100 headers and cuts each value at 2,000 characters. A long Content-Security-Policy can be cut. The report says when that happened.

  • The fetch service accepts https URLs on port 443 with a public hostname. It follows at most 5 redirects and stops after 8 seconds. It can be unavailable. Paste mode works without it.

  • Content-Security-Policy and Permissions-Policy are checked for presence. Their directives are not graded.

  • A report covers one response for one URL. Headers can differ by path, by request method and by status code.

  • An X-Robots-Tag finding describes the header. It does not show whether a page is indexed.

Methodology

Published by Michael Lip / AI Website Pipeline. Rules and sources reviewed 10 October 2026.

Paste mode runs in this browser. It splits the text into lines, skips the status line, reads each name: value line, joins a folded continuation line to the line before it, and lists every line it could not read. When the text holds more than one response, the last one is used.

URL mode sends the URL you enter to the fetch service, a Cloudflare Worker. The Worker checks the URL, makes one GET request per hop, cancels the body, and returns the status, the redirect hops and the header lines as JSON. The Worker code writes no logs and its log storage is switched off. The server you check receives a request from Cloudflare.

Every finding names the header it is about and links to the document that defines the rule. A header with no rule is listed without a finding.