HTTP Header Checker

Inspect server HTTP response headers, security policies (HSTS, CSP), caching directives (max-age, ETag), cookie security flags, and SEO tags.

Popular examples: https://google.comhttps://github.comhttps://cloudflare.com
Security Policy Audit

Inspects HSTS, Content-Security-Policy (CSP), X-Frame-Options, and Referrer-Policy.

Caching & Validation

Evaluates Cache-Control directives, max-age limits, ETags, Last-Modified, and Vary headers.

Cookie Security Flags

Parses Set-Cookie headers for Secure, HttpOnly, and SameSite attribute safety.

Fetching HTTP Response Headers…

Retrieving server response headers, analyzing security directives, and checking cache validity.

HTTP Status Code

200

Response Time

0 ms

Headers Extracted

0

Method Used

GET

Header KeyCategoryHeader ValueStatus
Exact Raw Server Response Headers

 
Security Headers Audit
Caching & Performance Audit
Set-Cookie Security Inspector
Cookie NameSecure FlagHttpOnly FlagSameSite AttributeSecurity Issues
Diagnostic Findings & SEO Advice
HTTP Response Headers inform search engines, CDNs, and browsers regarding security policies, MIME types, and caching rules.

What are HTTP Response Headers?

HTTP Response Headers are metadata fields sent by a web server to a browser or search engine crawler in response to an HTTP request. Headers specify content types, caching rules, cookie settings, and security policies.

Frequently Asked Questions (FAQ)

HSTS is a security header forcing browsers to communicate over HTTPS only.

It allows setting noindex or nofollow rules on non-HTML files like PDFs and images.