Request Configuration
Automatically follow redirect chains to inspect final destination headers.
Automatically retries with a GET request if the server rejects HEAD queries.
Click any sample URL preset to inspect headers instantly:
Some web application firewalls (WAF) return different headers based on the request User-Agent.
Response Workspace
Status200 OK
Latency0 ms
Security Audit0 / 7
ServerUnknown
Sending HTTP request to inspect response headers...
| Header Name | Value |
|---|
Security Headers Health Rating
0 of 7 Recommended Security Headers Implemented
Grade F
Passed Security Directives
Missing Security Directives & Fixes
Generated Terminal cURL Command:
Recent Inspected URLs:
Security Header Audit
Audits HSTS, Content-Security-Policy (CSP), X-Frame-Options, and Referrer-Policy to protect against Clickjacking and XSS.
Server & CORS Directives
Identify web server software (Nginx, Apache, Cloudflare), CORS access policies, and cache control lifetimes.
Terminal cURL Generator
Generates ready-to-run terminal cURL commands to reproduce header queries directly in bash or zsh.