How to use
- 1Enter the URL you want to inspect.
- 2Choose GET (full request) or HEAD (headers only, lighter).
- 3Review the final response headers and expand each redirect hop if needed.
- 4Check the security header audit and add whatever is missing.
Why check HTTP headers?
Response headers control caching, compression, redirects, cookies, indexing and browser security. They answer questions like: is Cache-Control set so static files are cached? Is content served with gzip or br (Content-Encoding)? Is an X-Robots-Tag: noindex accidentally blocking Google? Which server or CDN is in front of the site? Headers are invisible in the page itself, so a checker is the fastest way to see them.
The six security headers we audit
Strict-Transport-Security (HSTS) forces HTTPS; a typical value is max-age=31536000; includeSubDomains. Content-Security-Policy (CSP) restricts where scripts, styles and frames can load from and is the strongest defense against XSS. X-Frame-Options (DENY or SAMEORIGIN) prevents clickjacking; CSP frame-ancestors is the modern equivalent. X-Content-Type-Options: nosniff stops MIME-type sniffing. Referrer-Policy (strict-origin-when-cross-origin is a sensible default) limits what URL data leaks to other sites. Permissions-Policy turns off browser features you don’t use, such as camera=(), microphone=(), geolocation=().
How to add missing headers
On Apache use Header always set in .htaccess; on Nginx use add_header … always; in IIS add them under customHeaders in web.config. On Cloudflare Pages or Netlify, a _headers file does the job, and on Vercel use the headers key in vercel.json. Roll out CSP in Content-Security-Policy-Report-Only mode first so you don’t break scripts, and only add HSTS preload once every subdomain supports HTTPS.
Frequently asked questions
What is the difference between GET and HEAD?
HEAD asks only for headers, so it is faster and lighter. Some servers answer HEAD differently or reject it; if results look odd, switch to GET.
Why are headers shown for several hops?
If the URL redirects (e.g. http → https → www), each response has its own headers. Security headers matter most on the final hop that serves the page.
Do missing security headers hurt SEO?
Not directly; Google doesn’t rank on CSP or X-Frame-Options. They protect your visitors and your site, though, and HTTPS (enforced by HSTS) is a confirmed lightweight ranking signal.
Can I see request headers too?
This tool shows the response headers the server sends back. To see the headers your own browser sends, use our What Is My IP page, which shows your user agent and language.
Not happy with the results?
Talk to Webin Agency about fast, SEO-friendly websites, e-commerce and Google Ads management.