HTTP Headers

This HTTP headers checker fetches one URL and lists the response headers that came back, including the status and the final address after redirects.

This check runs on our server. The address you enter is used only for this check and is not stored.
Updated

This check runs on our server. The address you enter is used only for this check and is not stored.

How to use HTTP Headers

  1. Enter a web address.
  2. Tick the robot check and press Check.
  3. Read the status, the final URL, and the header list.

How it works

This check runs on our server. The address is not stored.

One GET is sent. Redirects are followed, up to the same hop limit as the Redirect Checker, and each hop must still be a public http or https address. The table is the headers on the last response, not the headers from the earlier hops. Those hops are on the Redirect Checker.

The body is discarded after the headers are read. It is not shown and not stored.

Examples

  • A page that redirects to HTTPS shows the final https:// URL and that response's headers, with status 200 when the last hop succeeded.
  • strict-transport-security is listed with a note that it tells browsers to keep using HTTPS for the host.
  • A header the page does not have a note for is still listed, name and value, with a blank note.

Limitations

  • One URL, one GET. There is no way to send a custom header or another method.
  • Headers set only by JavaScript in the browser are absent, because this request does not run JavaScript.
  • The server you read is ours, so the headers can differ from what your own browser receives through a CDN that varies by country.

Frequently asked questions

Why is there no content-security-policy?

The server did not send one on this response. The tool does not grade the site for that.

Can I see request headers?

No. The list is what the server sent back.

Do you store the URL?

No.

Often used together with the HTTP Headers.

  • Redirect Checker

    Every redirect hop, with status, Location, and time, up to 10 hops.

  • SSL Certificate

    Subject, alternative names, issuer, validity, and key type for the certificate on port 443.

  • HTTP Check

    HTTP status and response time from each available location, without downloading the page.