Free browser tool / response headers
HTTP header checker
See what a server sends and what it means.
Enter a public https URL or paste a block of response headers. The checker lists the header lines it receives, groups them, and reads the security, caching, cookie and robots headers. Each finding links to MDN, an RFC or another primary source.
A finding is a prompt to look at a header. It is not a vulnerability scan, and it says nothing about rankings or indexing.
Paste response headers
Header report
Findings
All header lines
| # | Header | Value | Group |
|---|
Names are shown in lower case. Field names are case-insensitive. RFC 9110, section 5.1.
Rules / every check has a source
What the checker looks at
The checker reads values, not only names. The table lists each check and the document it comes from. Where a header is present and no rule applies, the report shows it in the table without a finding.
| Header | What is checked | Source |
|---|---|---|
| strict-transport-security | Present. max-age is a number, is not zero, and is at least 31536000 seconds (1 year). includeSubDomains. With preload, max-age must be at least 31536000 and includeSubDomains must be present. | MDN, RFC 6797, hstspreload.org |
| content-security-policy | An enforced policy is present. A report-only policy alone is flagged, because it monitors violations without enforcing the policy. The directives are not graded. | MDN, MDN, report-only |
| x-content-type-options | The value is nosniff, the only directive MDN lists. | MDN |
| x-frame-options, frame-ancestors | X-Frame-Options is DENY or SAMEORIGIN. ALLOW-FROM is obsolete and modern browsers ignore the header when it is used. When an enforced policy has frame-ancestors, X-Frame-Options is ignored. | MDN, CSP Level 3 |
| referrer-policy | The value is a defined policy. unsafe-url and no-referrer-when-downgrade are called out. Without the header, browsers use strict-origin-when-cross-origin. | MDN |
| permissions-policy | Present or not. The directives are not graded. MDN marks the header as experimental. | MDN |
| cross-origin-opener-policy, cross-origin-embedder-policy, cross-origin-resource-policy | The value is one that MDN lists for the header. | MDN, COOP, COEP, CORP |
| cache-control | no-store next to public, max-age, s-maxage or immutable. public next to private. max-age given twice with different values. immutable without max-age. Expires next to max-age. No Cache-Control at all, which allows heuristic freshness. | RFC 9111, RFC 8246, MDN |
| set-cookie | Secure, HttpOnly and SameSite on each cookie. SameSite=None without Secure. The __Host- and __Secure- name prefix rules. Cookie values are masked and never shown. | MDN |
| x-robots-tag | noindex, nofollow and none are called out, and so is a rule addressed to one crawler. For the full rule list see the X-Robots-Tag reference. | |
| content-type | Present. For text/html, whether a charset parameter is given. | RFC 9110, HTML Standard |
| server, x-powered-by | A version number in Server, in paste mode only. X-Powered-By present. | RFC 9110, OWASP |
| x-xss-protection | An enabled filter is noted. MDN recommends Content-Security-Policy instead. | MDN |
Get the headers yourself
In a terminal,
curl -s -D - -o /dev/null https://your-site/prints the headers of a GET request.curl -sIsends a HEAD request instead, and some servers answer HEAD differently.In a browser, open the developer tools, select the Network panel, reload the page, select the document request and copy the response headers.
Paste the block above. The first line with the status code is optional. Request lines from
curl -voutput are skipped.
Related tools on this site are the meta robots checker, the robots.txt checker and the canonical tag checker.
Data / 20 sites, one GET each, 10 October 2026
A 20 site header snapshot
On 10 October 2026 each of 20 hosts was fetched once with one HTTPS GET to its root URL. The table counts how many of the 20 responses carried each of eight security headers. The hosts were picked by hand as sites that developers use. They are documentation, language, runtime and framework sites, GitHub, Hacker News and Cloudflare, two test hosts (example.com and httpbin.org), plus www.google.com and en.wikipedia.org. This is not a random sample and it does not describe the web as a whole.
| Security header | Sites sending it, of 20 | Share of the 20 |
|---|---|---|
| strict-transport-security | 14 | 70% |
| x-content-type-options | 10 | 50% |
| content-security-policy | 8 | 40% |
| x-frame-options | 8 | 40% |
| referrer-policy | 6 | 30% |
| cross-origin-opener-policy | 2 | 10% |
| cross-origin-resource-policy | 2 | 10% |
| permissions-policy | 1 | 5% |
Source for every figure in this section is header-survey-2026-10-10.json, 20 hosts, one HTTPS GET each, captured 10 October 2026.
In this capture www.google.com sent no Strict-Transport-Security header. Of the 7 responses whose Server value was cloudflare, 5 carried Strict-Transport-Security and 2 did not (example.com and astro.build). 5 of the 20 responses carried none of the eight headers (example.com, httpbin.org, blog.rust-lang.org, astro.build and www.rust-lang.org). One GET per host is a single observation, so read each row as what that one response contained, not as a statement about the site.
The 20 hosts and what each response carried
| Host | Of the eight | Headers present |
|---|---|---|
| example.com | 0 | none |
| httpbin.org | 0 | none |
| developer.mozilla.org | 5 | strict-transport-security, x-content-type-options, content-security-policy, x-frame-options, referrer-policy |
| www.google.com | 1 | x-frame-options |
| en.wikipedia.org | 3 | strict-transport-security, x-content-type-options, content-security-policy |
| github.com | 5 | strict-transport-security, x-content-type-options, content-security-policy, x-frame-options, referrer-policy |
| news.ycombinator.com | 5 | strict-transport-security, x-content-type-options, content-security-policy, x-frame-options, referrer-policy |
| www.python.org | 2 | strict-transport-security, x-frame-options |
| nodejs.org | 2 | strict-transport-security, x-content-type-options |
| blog.rust-lang.org | 0 | none |
| web.dev | 3 | strict-transport-security, x-content-type-options, content-security-policy |
| developers.cloudflare.com | 3 | strict-transport-security, x-content-type-options, content-security-policy |
| www.cloudflare.com | 8 | strict-transport-security, x-content-type-options, content-security-policy, x-frame-options, referrer-policy, cross-origin-opener-policy, cross-origin-resource-policy, permissions-policy |
| tailwindcss.com | 1 | strict-transport-security |
| vitejs.dev | 1 | strict-transport-security |
| nextjs.org | 5 | strict-transport-security, x-content-type-options, content-security-policy, x-frame-options, referrer-policy |
| astro.build | 0 | none |
| www.rust-lang.org | 0 | none |
| deno.com | 6 | strict-transport-security, x-content-type-options, x-frame-options, referrer-policy, cross-origin-opener-policy, cross-origin-resource-policy |
| bun.sh | 1 | strict-transport-security |
Method. One HTTPS GET per host on 10 October 2026, recorded as the host, the final status, the list of the eight headers present, the Server value and whether Set-Cookie was sent. The data file was saved at 05:24 UTC. It does not record the request times or the User-Agent string. vitejs.dev redirects to vite.dev and is recorded with status 200, so redirects were followed. As a check, 12 of the 20 hosts were fetched again with curl (GET) at 07:43 UTC the same day, and all 12 returned the same set of the eight headers.
Limits
URL mode shows what the server sent to our fetch service. The request comes from a Cloudflare data centre with the User-Agent
AIWebsitePipeline-HeaderChecker/1.0. A server can send different headers to your browser. In a test on 10 October 2026 with 6 large sites, 2 answered the fetch service with an error status (HTTP 429 and HTTP 419) while a direct curl request received HTTP 200.Cloudflare carries the request and changes part of the answer. The Server value is replaced, cf-ray and cf-cache-status are added, content-encoding, content-length, accept-ranges and alt-svc can be missing, and a strong ETag can arrive as a weak one (W/ prefix). The report marks these rows as "fetch service". Paste mode has no such changes.
In URL mode each Set-Cookie line is kept as its own row. Other repeated header lines arrive joined into one value with commas, which HTTP allows. RFC 9110, section 5.3. Paste mode keeps every line you paste.
The fetch service returns at most 100 headers and cuts each value at 2,000 characters. A long Content-Security-Policy can be cut. The report says when that happened.
The fetch service accepts https URLs on port 443 with a public hostname. It follows at most 5 redirects and stops after 8 seconds. It can be unavailable. Paste mode works without it.
Content-Security-Policy and Permissions-Policy are checked for presence. Their directives are not graded.
A report covers one response for one URL. Headers can differ by path, by request method and by status code.
An X-Robots-Tag finding describes the header. It does not show whether a page is indexed.
Methodology
Published by Michael Lip / AI Website Pipeline. Rules and sources reviewed 10 October 2026.
Paste mode runs in this browser. It splits the text into lines, skips the status line, reads each name: value line, joins a folded continuation line to the line before it, and lists every line it could not read. When the text holds more than one response, the last one is used.
URL mode sends the URL you enter to the fetch service, a Cloudflare Worker. The Worker checks the URL, makes one GET request per hop, cancels the body, and returns the status, the redirect hops and the header lines as JSON. The Worker code writes no logs and its log storage is switched off. The server you check receives a request from Cloudflare.
Every finding names the header it is about and links to the document that defines the rule. A header with no rule is listed without a finding.