HTTP header checker

See every response header a URL sends, plus a quick review of security headers.

Checked from Frankfurt, EU

Security headers to look for

Strict-Transport-Security forces HTTPS. Content-Security-Policy limits where scripts can load from. X-Content-Type-Options stops MIME sniffing. X-Frame-Options or frame-ancestors prevents clickjacking. Referrer-Policy limits what you leak to other sites.

Frequently asked questions

Does the tool follow redirects?+

It shows the first response and the redirect target. Check the target URL separately to see its headers.

Monitor this site automatically

Get an alert on Telegram, Slack or email the moment it goes down. 10 monitors free, checked from the EU.

Start free – no card ↗